APT41

THREAT ACTOR PROFILE

APT41

APT41

APT41

APT41 is a Chinese state-sponsored group active since 2012 that runs both espionage and financially motivated operations. It has hit healthcare, technology, government and video game companies in more than 14 countries, and its recent tooling leans toward Linux implants and cloud credential theft.

China

Healthcare / IT / Government

First seen

2012

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Winnti, BARIUM and nineteen other vendor names

APT41 has 21 names in our record. Some, like Winnti Group, come from the malware the group made famous, and several vendors track it under two labels each, such as Microsoft (BARIUM, Brass Typhoon) and Trend Micro (Earth Baku, Earth Freybug).

Proofpoint's TA415 is listed here too. Proofpoint describes it as overlapping with APT41, Brass Typhoon and Wicked Panda rather than identical, so treat its reports as related activity. All of these names resolve to one entry in our directory of threat actors.

-

-

-

-

-

-

-

-

-

-

-

GROUP PROFILE

State espionage with a side business in cybercrime

APT41 stands out for doing both jobs: intelligence collection for the state and profit-driven intrusions such as ransomware and cryptojacking. Our record ties it to supply chain attacks, custom malware and, in 2024, activity against shipping and media companies.

Recent reporting shows the group going after a U.S. policy non-profit, U.S. government and academic targets with U.S.-China trade lures, government IT services in Africa, and Taiwanese government entities.

Its 2026 tooling moved further into Linux and cloud. A backdoor analyzed by Breakglass Intelligence had zero VirusTotal detections and went straight for cloud instance metadata to steal credentials.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

-

-

-

-

ATTACK LIFECYCLE

Old web bugs in, cloud credentials out

The stages below come from APT41 intrusions documented in posts we track on our IOC Hunter feed, from 2025 into 2026.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

Melofee, a Winnti ELF build and ToughProgress

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Confluence, Log4j, Struts and GoAhead flaws

All four were used for initial access against a U.S. policy non-profit in April 2025, according to Hive Pro's advisory.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

APT41

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

APT41

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

APT41

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

APT41

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Quieter Linux and cloud tooling through 2026

The latest reports show APT41-linked activity shifting toward Linux implants and cloud credentials, with C2 designed to stay invisible to scanners.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

APT41

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

APT41

IOC set, full IP, host and hash history.