APT41 Cyber Attacks: History, Operations, and Full TTP Analysis
ID: 9e372da1-828f-564f-94ac-76da3bf72778
STIX ID: report--9e372da1-828f-564f-94ac-76da3bf72778
Feed Name: Resources-2
Date Published: 2025-11-24
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
APT41 is a long-running, highly capable threat actor conducting simultaneous espionage and financially motivated operations since at least 2007; the report catalogs their major campaigns, rapid weaponization of critical vulnerabilities (notably Log4Shell, Citrix ADC, and Zoho ManageEngine), use of living-off-the-land techniques, credential harvesting (Mimikatz, ntdsutil), web shells and service-based persistence, Cobalt Strike deployments, and exfiltration to legitimate cloud services like OneDrive, and recommends validating defenses via the Picus platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
