Dark Web Profile: APT41
ID: 9391d697-e973-5d66-ab8b-90e29c71477f
STIX ID: report--9391d697-e973-5d66-ab8b-90e29c71477f
Feed Name: SOCRadar Blog
This profile details APT41’s dual-purpose operations — state-aligned espionage and financially motivated cybercrime — highlighting an exploit-first intrusion style, long-term persistence, rapid weaponization of disclosed vulnerabilities (e.g., Log4Shell), use of living-off-the-land techniques, credential theft, web shells, and novel C2 channels (notably Google Calendar via the TOUGHPROGRESS campaign). It documents notable campaigns (US state government intrusions, trade-policy phishing, TOUGHPROGRESS) and provides mitigation recommendations such as faster patching, phishing-resistant MFA, detection of native tooling abuse, and cloud monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
