During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.4
group
APT41 G0096
- Created
- 23 September 2019
- Last modified
- 31 July 2026
- Aliases
- APT41 · Wicked Panda · Brass Typhoon · BARIUM
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0096
APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.567
APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.8
During C0017, APT41 copied the SAM and SYSTEM Registry hives for credential harvesting.9
APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.10
APT41 has uploaded files and data from a compromised host.11
During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.12
APT41 used the Steam community page as a fallback mechanism for C2.13
Standing G0096
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
98th percentile · 98% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
100th percentile · None of the 176 ATT&CK groups has more tactics spanned — the highest in the population.
99th percentile · 99% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
67th percentile · 67% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0096
2785 distinct rules cover the 82 techniques recorded for this group. The 3346 technique-to-rule mappings resolve to 2785 distinct rules, because one rule can cover several techniques. 1815 Sigma · 970 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org