Five Chinese hackers, said to be part of APT41, were charged this week by the U.S. Department of Justice. U.S. authorities accused the hackers of a long-running campaign of attacks on more than 100 companies. The hackers are said to have used phishing emails and carried out “supply chain” attacks to steal data from companies and customers. One of the alleged members of APT41 was the owner of a Chinese company that provided services antivirus.

The Chinese hackers belong to the state-run hacking group “APT41” (also known as “Barium”, “Winnti”, “Wicked Panda” and “Wicked Spider”) and gained access to target companies with the aim of stealing source code and many other data.
APT41 hackers have been particularly active for several years. Security FireEye has described the group's attacks as "one of the largest espionage campaigns by Chinese hackers."
According to the US Department of Justice, APT41 hid malware in fake resumes sent to targets. It also carried out more sophisticated supply chain attacks (hacking software providers and altering software by modifying the code with malware).
“The software company – unaware of the changes to its product – distributes the modified software to customers, who in turn install the malware on their own computers,” the court documents explain.
As mentioned above, one of the men said to be part of APT41, 35-year-old Tan DaiLin, had also been in the news for KrebsOnSecurity in 2012, when the site tried to shed light on a Chinese antivirus product called Anvisoft. At the time, the product had been “authorized” and deemed safe. However, the company did not respond to user complaints and questions about its leadership and origins.
Anvisoft had said it was based in California and Canada. However, researchers discovered that the company's trademark appeared in trademark registration records in Chengdu in Sichuan province, China.
A detailed check of Anvisoft's website showed that the company's domain was originally created by Tan DaiLin, a well-known Chinese hacker, who used the aliases "Wicked Rose" and "Withered Rose".

This story brought to light a iDefense detailing DaiLin’s role as government hacking four-person The group’s name was NCPH (short for Network Crack Program Hacker). According to iDefense, in 2006 the group created a rootkit that exploited a zero-day vulnerability in Microsoft Word and was used in attacks on U.S. companies.
According to krebsonsecurity, when Anvisoft was first analyzed on Virustotal.com in 2012, no antivirus products detected it as suspicious or malicious. However, in the following days, multiple programs detected at least two trojans designed to steal passwords from various online gaming platforms.
According to security researchers and US prosecutors, APT41 often creates products (such as DaiLin's Anvisoft) that appear legitimate, while in fact infecting victims.
