← Back to all campaigns
ActiveMITRE ATT&CK

C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).

First observedMay 1, 2021
Last observedFeb 1, 2022
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting vari...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

APT41 attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

C0017 last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

C0017 first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Malware and tools 32

  • ASPXSpyMalware | APT41
  • BLACKCOFFEEMalware | APT41
  • China ChopperMalware | APT41
  • Cobalt StrikeMalware | APT41
  • DUSTPANMalware | APT41
  • DUSTTRAPMalware | APT41
  • DerusbiMalware | APT41
  • KEYPLUGMalware | APT41
  • LightSpyMalware | APT41
  • MESSAGETAPMalware | APT41
  • MOPSLEDMalware | APT41
  • PlugXMalware | APT41

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.

Continue investigating

Campaigns with shared actors