ATT&CKReferencesapt41_mandiant

apt41_mandiant

Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1037
Boot or Logon Initialization Scripts
GroupAPT41

APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit.

T1484.001
Group Policy Modification
GroupAPT41

APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware.

T1496.001
Compute Hijacking
GroupAPT41

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.

T1684.001
Impersonation
GroupAPT41

APT41 impersonated an employee at a video game developer company to send phishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.