logo

APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials

ID: 622a7a27-a792-59b9-b218-13edbe210716

STIX ID: report--622a7a27-a792-59b9-b218-13edbe210716

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Elizabeth Montalbano

...
...

APT41 is using a stealthy, statically-linked ELF backdoor against Linux cloud instances to harvest cloud provider credentials (AWS, GCP, Azure, Alibaba); the malware uses SMTP (port 25) as a covert C2 channel, leverages typosquatted domains to blend with legitimate traffic, showed zero VirusTotal detections at analysis, and Breakglass Intelligence provides network-, host-, and cloud-native detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.