Overview: APT41, also known as Brass Typhoon. Espionage targeting healthcare, telecoms, and the high-tech sector, with a target of stealing intellectual property and conducting surveillance against its victims.
Suspected Attribution: China-based
Target Sectors: This threat actor steals intellectual property through intrusions, seeks manipulation of virtual currencies and deployment of ransomware. Ops against higher education, travel services, and news/media all hint the group tracks individuals and conducts surveillance.
Attack Vectors: Spearphishing emails with attachments like compiled HTML (.chm) files for initial compromise. Once inside, they use backdoors, credential stealers, keyloggers, rootkits, and Master Boot Record (MBR) bootkits to hide and maintain persistence.
Associated Malware: At least 46 different code families and tools.