Overview
APT41 (MITRE ATT&CK ID G0096) is a threat group researchers have assessed as a Chinese state-sponsored espionage group that also conducts financially motivated operations, per MITRE ATT&CK’s group profile. Active since at least 2012, MITRE’s data describes APT41 as having been observed targeting healthcare, telecom, technology, finance, education, retail, and video game industries across 14 countries. MITRE notes the group is characterized by using a wide range of malware and tools to complete mission objectives, and that its activity overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.
Attribution caveat
MITRE ATT&CK’s phrasing — “researchers have assessed” — reflects that this is the security research community’s analytical conclusion as MITRE has synthesized it, not an independently confirmed government attribution in the way some other nation-state groups (e.g. APT29’s SolarWinds attribution) carry formal state-level statements.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested data links APT41 to malware including ShadowPad, KEYPLUG, PlugX, China Chopper, LightSpy, DUSTPAN, DUSTTRAP, Derusbi, BLACKCOFFEE, and MESSAGETAP, alongside dual-use tools like Cobalt Strike, Mimikatz, Impacket, and Empire.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to APT41 in our data include Accessibility Features (T1546.008), Additional Local or Domain Groups (T1098.007), Archive via Utility (T1560.001), BITS Jobs (T1197), Boot or Logon Initialization Scripts (T1037), Bootkit (T1542.003), Brute Force (T1110), and Clear Command History (T1070.003).
Related campaigns
Per MITRE ATT&CK’s relationship data, APT41 is linked to “APT41 DUST” and campaign C0017 in our ingested data.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2012” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and MITRE’s own description flags the state-sponsorship assessment as researcher consensus rather than a formal government attribution.
Frequently Asked Questions
What is APT41? A group researchers assess as Chinese state-sponsored, per MITRE ATT&CK, that also conducts financially motivated cybercrime — active since at least 2012 across 14 countries and multiple industries.
Does APT41 only do espionage? No — MITRE ATT&CK’s profile explicitly notes the group conducts both state-sponsored espionage and financially motivated operations, an unusual dual mandate among the groups MITRE tracks.
What malware is APT41 linked to? Per MITRE ATT&CK’s relationship data: ShadowPad, KEYPLUG, PlugX, China Chopper, LightSpy, and DUSTTRAP, among others.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0096, aggregated August 30, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.