Chinese hackers APT41 are targeting organizations in Italy, Spain, Taiwan, Thailand, Turkey, and the United Kingdom, operating in the global shipping and logistics, media and entertainment, technology , and automotive sectors.
According to a new report from Mandiant, the Chinese group infiltrated the organizations' networks and maintained prolonged, unauthorized access since 2023. As a result, the hackers were able to steal sensitive data for a long time.
The cybersecurity firm says APT41 is one of the most dangerous Chinese hacking groups due to its use of non-public malware typically intended for espionage operations as part of state-sponsored hacking operations.
See also: Chinese hackers distribute SpiceRAT and SugarGh0st malware

APT41 hackers' attacks include the use of web shells (ANTSWORD and BLUEBEAM), custom droppers (DUSTPAN and DUSTTRAP), and publicly available tools (SQLULDR2 and PINEGROVE) to achieve persistence, deliver additional malicious payloads, and extract data.
The web shells act as a conduit for the DUSTPAN (aka StealthVector) dropper that is responsible for loading the Cobalt Strike Beacon. This process is done for command-and-control (C2) communication. This is followed by the deployment of the DUSTTRAP dropper after lateral movement.
The DUSTTRAP dropper is configured to decrypt a malicious payload and execute it in memory. This, in turn, establishes contact with a server controlled by APT41 hackers or a compromised Google Workspace. The goal is to hide its malicious activities.
See also: Chinese hackers UNC3886 exploit Fortinet, Ivanti and VMware vulnerabilities
DUSTTRAP also has 15 plugins capable of executing shell commands, file system operations, terminating processes, recording keystrokes, taking screenshots, collecting system information, and modifying the Windows registry.
Google said the identified accounts have been patched to prevent unauthorized access. However, it did not disclose how many accounts were affected.

Chinese hackers APT41 use both SQLULDR2 to extract data from Oracle databases and PINEGROVE to transmit large volumes of sensitive data from compromised networks.
See also: Chinese hackers used F5 BIG-IP devices for cyber espionage
The attacks by APT41 hackers highlight the need for organizations to have robust cybersecurity measures in place. With their ability to target multiple industries across countries and their use of advanced techniques and malware , it is vital for companies to continually update their defenses against such threats. As long as hacking groups like APT41 continue to operate, the importance of cybersecurity cannot be overstated . Overall, it is important for organizations to remain vigilant and take the necessary precautions to protect their sensitive data from potential cyberattacks. Staying up-to-date with the latest security and conducting regular assessments measures can help mitigate risk. Security should be a top priority for all businesses in today’s digital age.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
