logo

APT41 Cyber Attacks: History, Operations, and Full TTP Analysis

ID: 9e372da1-828f-564f-94ac-76da3bf72778

STIX ID: report--9e372da1-828f-564f-94ac-76da3bf72778

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-11-24

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

APT41 is a long-running, highly capable threat actor conducting simultaneous espionage and financially motivated operations since at least 2007; the report catalogs their major campaigns, rapid weaponization of critical vulnerabilities (notably Log4Shell, Citrix ADC, and Zoho ManageEngine), use of living-off-the-land techniques, credential harvesting (Mimikatz, ntdsutil), web shells and service-based persistence, Cobalt Strike deployments, and exfiltration to legitimate cloud services like OneDrive, and recommends validating defenses via the Picus platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.