← Back to all threat actors

APT41

Also known as Wicked Panda, Brass Typhoon, BARIUM
Tracked as G0096

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
CN
Sectors
healthcare, technology, telecom, gaming
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Wicked Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Brass Typhoon

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BARIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0096

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2021-44228 linked to this actor
Cataloged
CVECVE-2021-26084 linked to this actor
Cataloged
CVECVE-2022-26134 linked to this actor
Last observed
CampaignAPT41 DUST

APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as sh…

Last observed
CampaignC0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT41Canonical Name
BARIUMAlias
Brass TyphoonAlias
Wicked PandaAlias
G0096Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...