logo

APT41 Infiltrates Networks in Italy, Spain, Taiwan, Turkey, and the U.K.

ID: d15d0ca4-e2dc-5e01-8f10-3c4771beee3f

STIX ID: report--d15d0ca4-e2dc-5e01-8f10-3c4771beee3f

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-07-19

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Mandiant reports a sustained APT41 cyber-espionage campaign since 2023 targeting organizations across shipping, media, technology, and automotive sectors in multiple countries using web shells (ANTSWORD, BLUEBEAM), droppers (DUSTPAN/StealthVector and DUSTTRAP), Cobalt Strike, SQLULDR2 and PINEGROVE for data theft and exfiltration (including OneDrive and Oracle DB abuse), with components signed by presumably stolen certificates; separately, Sygnia attributes a sophisticated GhostEmperor campaign that installs the Demodex kernel rootkit using Cheat Engine to bypass driver signature enforcement, employing multi-stage implants and anti-analysis techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.