logo

APT41 World Tour 2021 on a tight schedule

ID: 18ff909e-7625-529d-9cf3-7733ab9634f8

STIX ID: report--18ff909e-7625-529d-9cf3-7733ab9634f8

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2022-08-18

Date Updated: 2026-04-27

...
...

Group-IB provides a consolidated analysis of APT41 activity during 2021, describing multiple global intrusion campaigns that leveraged SQL injection, public-facing application exploits (including ProxyLogon), and Cobalt Strike beacons. The report maps observed TTPs to MITRE ATT&CK, lists commands and artifacts used (PowerShell reverse shells, certutil Base64 payload assembly, scheduled tasks, service creation, credential dumping via ntds.dit/LSASS/Mimikatz), supplies IOCs and Cobalt Strike configs, notes attacker infrastructure patterns (CloudFlare-protected C2, custom SSL certs), and offers hunting guidance and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.