Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0096
MITRE ATT&CK Group

APT41 (G0096)

Wicked PandaBrass TyphoonBARIUM
ShareXLinkedInRedditHN

[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. [APT41](https://attack.mitre.org/groups/G0096) overlaps at least partially with public reporting on groups including BARIUM and [Winnti Group](https://attack.mitre.org/groups/G0044).(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 2021)

▪Techniques used (82)

T1078Valid AccountsT1082System Information DiscoveryT1195.002Compromise Software Supply ChainT1069Permission Groups DiscoveryT1595.003Wordlist ScanningT1059.001PowerShellT1014RootkitT1087.002Domain AccountT1555.003Credentials from Web BrowsersT1036.005Match Legitimate Resource Name or LocationT1543.003Windows ServiceT1071.002File Transfer ProtocolsT1018Remote System DiscoveryT1027.002Software PackingT1553.002Code SigningT1596.005Scan DatabasesT1588.002ToolT1098.007Additional Local or Domain GroupsT1021.002SMB/Windows Admin SharesT1037Boot or Logon Initialization ScriptsT1136.001Local AccountT1542.003BootkitT1685.005Clear Windows Event LogsT1087.001Local AccountT1071.001Web ProtocolsT1135Network Share DiscoveryT1599Network Boundary BridgingT1480.001Environmental KeyingT1484.001Group Policy ModificationT1595.002Vulnerability ScanningT1005Data from Local SystemT1133External Remote ServicesT1070.004File DeletionT1566.001Spearphishing AttachmentT1685Disable or Modify ToolsT1053.005Scheduled TaskT1547.001Registry Run Keys / Startup FolderT1546.008Accessibility FeaturesT1110Brute ForceT1550.002Pass the HashT1574.006Dynamic Linker HijackingT1059.003Windows Command ShellT1003.002Security Account ManagerT1568.002Domain Generation AlgorithmsT1569.002Service ExecutionT1071.004DNST1046Network Service DiscoveryT1560.001Archive via UtilityT1218.011Rundll32T1102.001Dead Drop ResolverT1008Fallback ChannelsT1555Credentials from Password StoresT1496.001Compute HijackingT1003.003NTDST1049System Network Connections DiscoveryT1059.004Unix ShellT1486Data Encrypted for ImpactT1016System Network Configuration DiscoveryT1033System Owner/User DiscoveryT1105Ingress Tool TransferT1203Exploitation for Client ExecutionT1218.001Compiled HTML FileT1112Modify RegistryT1090ProxyT1003.001LSASS MemoryT1684.001ImpersonationT1213.003Code RepositoriesT1197BITS JobsT1012Query RegistryT1083File and Directory DiscoveryT1055Process InjectionT1021.001Remote Desktop ProtocolT1190Exploit Public-Facing ApplicationT1570Lateral Tool TransferT1027Obfuscated Files or InformationT1104Multi-Stage ChannelsT1030Data Transfer Size LimitsT1047Windows Management InstrumentationT1056.001KeyloggingT1070.003Clear Command HistoryT1036.004Masquerade Task or ServiceT1574.001DLL

▪Software used (32)

S0073ASPXSpymalwareS0190BITSAdmintoolS0013PlugXmalwareS0357ImpackettoolS0032gh0st RATmalwareS0104netstattoolS0194PowerSploittoolS0412ZxShellmalwareS1051KEYPLUGmalwareS0097PingtoolS1185LightSpymalwareS1158DUSTPANmalwareS0039NettoolS0100ipconfigtoolS0225sqlmaptoolS0020China ChoppermalwareS0596ShadowPadmalwareS0443MESSAGETAPmalwareS0002MimikatztoolS0160certutiltoolS0385njRATmalwareS0363EmpiretoolS0154Cobalt StrikemalwareS0006pwdumptoolS0069BLACKCOFFEEmalwareS1221MOPSLEDmalwareS0112ROCKBOOTmalwareS0105dsquerytoolS0430Winnti for LinuxmalwareS1159DUSTTRAPmalwareS0021DerusbimalwareS0095ftptool
G0096on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.