Chinese hackers APT41 (also known as Brass Typhoon, Earth Baku, Wicked Panda or Winnti) have been linked to attacks on the gambling and gaming industries.

“Over a period of at least six months, the attackers gathered valuable information from the targeted company, including network configurations, user passwords, and secrets from the LSASS process,” said Ido Naor, co-founder and CEO of Security Joes.
According to the researchers, the attackers were constantly updating tools their. “By observing the actions of network defenders, they changed their strategies and tools to bypass detection and maintain permanent access to the compromised network.”
See also: What tools are used by the APT41 hacker group
Researchers observed a multi-stage attack that lasted nearly nine months and shared commonalities with Operation Crimson Palace, which Sophos tracked.
Naor said the company responded to the incident four months ago. “This time we suspect with high confidence that the APT41 hackers had financial gain.”
The campaign was designed with stealth in mind. The group used a custom toolkit that not only bypassed security, but also collected critical information and created covert channels for permanent remote access.
Security Joes explained that the Chinese hackers APT41 are extremely methodical and knowledgeable. They carry out espionage and supply chain attacks, leading to intellectual property theft and financially motivated attacks (e.g. ransomware and cryptocurrency mining).
See also: What tools are used by the APT41 hacker group
It is believed (without being confirmed) that the initial access is via spear-phishing email.
“Once inside the targeted infrastructure, the attackers executed a DCSync, aiming to harvest password hashes for services and accounts to extend their access,” the company said in its report. “With these credentials, they established persistence and maintained control of the network, focusing particularly on administrator and developer accounts.”
The attackers are said to have methodically carried out their activities, with the ultimate goal of downloading and executing additional payloads.

Some of the techniques used by Chinese APT41 hackers include Phantom DLL Hijacking , using the legitimate wmic.exe utility , and abusing their access to service accounts with administrative privileges to enable execution.
The next stage is a malicious DLL file named TSVIPSrv.dll that is retrieved via the SMB protocol, after which the payload establishes contact with a hard-coded command-and-control (C2) server.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
You can learn more about the attack in the Security Joes report
See also: APT41 hacking gang uses StealthVector malware
Chinese hackers
Chinese hackers will continue to pose a significant threat in the world of cyberwarfare. It is essential for governments and organizations to remain vigilant and take the necessary measures to protect against potential attacks. In addition, countries must work together to address cyber threats and promote a secure digital landscape.
Taking some basic cybersecurity can also help prevent attacks. Creating strong passwords, avoiding suspicious emails, creating backups, using antivirus software, updating software and applications, and staying informed about the latest cyber threats can go a long way in protecting against Chinese hackers and other cyber attackers.
Source: thehackernews.com
