logo

China's APT41 Targets Global Logistics, Utilities Companies

ID: 6e07d31e-e428-5cdc-8392-33eacd393699

STIX ID: report--6e07d31e-e428-5cdc-8392-33eacd393699

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-07-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Mandiant (in collaboration with Google TAG) reports that APT41 has conducted a sustained espionage campaign since early 2023 against organizations in shipping/logistics, media/entertainment, technology, and automotive sectors across countries including the UK, Italy, Spain, Taiwan, Thailand, and Turkey. The actor employed custom web shells (AntsWord, BlueBeam), a dropper (DustPan), a multi-stage in-memory plugin framework (DustTrap), specialized exfiltration tools (PineGrove, SQLULDR2) and Beacon to maintain prolonged access and exfiltrate sensitive data, with evidence of broad geographic targeting and sophisticated post-compromise tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.