#apt41
With China's ginormous investments in Africa, it was only natural that the APTs would follow

securelist.com/apt41-in-afr...
SOC files: an APT41 attack on government IT services in Africa
Kaspersky experts analyze an incident that saw APT41 launch a targeted attack on government IT services in Africa.
securelist.com
July 21, 2025 at 3:00 PM
Veeeery excited to attend and present at @pivotcon.bsky.social on attributing an extremely weird campaign to China-aligned TA415 (APT41/Brass Typhoon), as well as covering subsequent targeted activity linked to this actor!
"You-Know-Who’s Cyber Crew: Attributing Widespread Voldemort Phishing Campaign to China-nexus TA415"

Mark Kelly, Staff Threat Researcher, ProofPoint (@markkelly0x , @mkyo.bsky.social )
17/18
March 7, 2025 at 3:07 PM
˚✦APT33 ✫ ·
.
   ˚ · . ✷ ✦APT35 ˚ .
✫  *  ⠀.
⠀⠀.      * ⠀⠀ .
   *      . ✦APT38
✦ APT41 .  *  ˚   ゚.
   ✫ ·      ˚
╱|、
(˚ˎ 。7
|、˜〵
じしˍ,)ノ
November 16, 2024 at 6:17 PM
Spoofing Call Stacks To Confuse EDRs : labs.withsecure.com/publications...

Call stack spoofing explained using APT41 malware : cybergeeks.tech/call-stack-s...
November 23, 2024 at 3:26 PM
The Google Cloud security team has spotted Chinese cyber-espionage group APT41 deploy the TOUGHPROGRESS malware in recent attacks, a backdoor that uses Google Calendar as a command-and-control channel

cloud.google.com/blog/topics/...
May 29, 2025 at 12:13 PM
Google Calendar C2 👀

cloud.google.com/blog/topics/...
Mark Your Calendar: APT41 Innovative Tactics | Google Cloud Blog
cloud.google.com
May 29, 2025 at 12:41 PM
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
thehackernews.com
March 4, 2026 at 9:08 AM
🚨 Heads up! 🚨 APT41 is using Google Calendar 🗓️ as their latest C2 trick. GTIG just pulled back the curtain 🎭 on the TOUGHPROGRESS malware campaign and how we shut it down 💪. Dive into the details here: 🚀https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics
May 28, 2025 at 2:11 PM
Excellente petite vidéo sur le groupe d'attaquants chinois APT41 qui en 17 minutes fait une très bonne vulgarisation d'analyse de la menace cyber 👍🤖

#CTI

youtu.be/ftMNQGbvCiA?...
Ces hackers chinois vous ont sûrement déjà piraté… (APT41)
Merci à Emma Matelas de sponsoriser cette vidéo (et d’améliorer mon sommeil depuis déjà quelques temps), des réductions sur les matelas avec le code SYLVQIN ...
youtu.be
October 30, 2023 at 8:38 PM
APT41 (Brass Typhoon), a Chinese group active since 2012, blends state-sponsored espionage (telecom, tech, automotive) with cybercrime (gaming, finance). Sophisticated operations and blurred attribution make them a persistent threat.#APT41BrassTyphoon
April 14, 2025 at 4:03 PM
Catherine Dupont-Gagnon alerte sur une nouvelle tactique d’espionnage : l’exploitation de Google Calendar par le groupe APT41, lié à la Chine. moncarnet.com/2025/06/10/c...
June 10, 2025 at 11:07 AM
Ok, but China is still a threat. To our infrastructure and to private businesses. Also, remember Taiwan?

We can do this all day

malpedia.caad.fkie.fraunhofer.de/actor/apt41
APT41 (Threat Actor)
APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.
malpedia.caad.fkie.fraunhofer.de
December 27, 2024 at 4:16 AM
Dive into our latest blog post on APT41 and the innovative tactics behind their sophisticated malware campaigns! 🦠💻 Learn more: https://innovirtuoso.com/cybersecurity-analysis/apt41-innovative-tactics-of-a-sophisticated-malware-campaign/ #Cybersecurity #APT41 #Malware
APT41: Innovative Tactics of a Malware Campaign
APT41, a sophisticated cyber threat actor from China, is known for its innovative malware campaigns targeting government, healthcare, technology sectors.
innovirtuoso.com
February 16, 2026 at 4:16 PM
APT41/RedGolf Infrastructure Briefly Exposed: Fortinet Zero-Days Targeted Shiseido
APT41/RedGolf Infrastructure Briefly Exposed: Fortinet Zero-Days Targeted Shiseido
A misconfiguration exposed APT41 tools targeting Shiseido, revealing Fortinet exploit scripts, webshells, and reconnaissance tactics.
securityonline.info
April 21, 2025 at 4:56 AM
🚨 Chinese hackers impersonate US Congressman in malware campaign

Chinese-linked APT41 sent malware-laced emails posing as Congressman John #Moolenaar to trade groups, law firms and agencies ahead of US–China trade talks.

#ransomNews #apt41 #cyberespionage
September 8, 2025 at 5:37 PM
The Chinese APT41 hacking group uses a new malware named 'ToughProgress' that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service.
APT41 malware abuses Google Calendar for stealthy C2 communication
The Chinese APT41 hacking group uses a new malware named 'ToughProgress' that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service.
www.bleepingcomputer.com
May 28, 2025 at 10:04 PM
A collaborative deep dive into clustering & attributing modern threat ecosystems, featuring a case study on APT41.

Learn more here: web.cvent.com/event/3854aa...
CyCon Agenda - CyCon 2026: Securing Tomorrow
web.cvent.com
April 3, 2026 at 3:26 PM
Mark was literally on my team for two seconds before solidly attributing the Voldemort activity me and @ffforward.bsky.social worked to TA415 (APT41)

Then me and Tommy went back to ecrime 😂

www.proofpoint.com/us/blog/thre...
The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers “Voldemort” | Proofpoint US
Research update (October 22nd, 2024) Proofpoint analysts now attribute this campaign to the China-aligned threat group TA415 (also known as APT41 and Brass Typhoon).  This attribution is based on m...
www.proofpoint.com
December 4, 2024 at 12:41 AM
Android spyware is being utilized by Chinese espionage group APT41. These pieces of spyware attempt to pass themselves off as messaging/keyboard apps and system apps. They extract a wide range of data from personal and work devices.
Chinese APT41 Linked to WyrmSpy and DragonEgg Surveillanceware
Lookout attributed WyrmSpy and DragonEgg to APT41 due to overlapping Android signing certificates
www.infosecurity-magazine.com
July 19, 2023 at 7:49 PM
Google Researchers Detailed Tools Used by APT41 Hacker Group
Google Researchers Detailed Tools Used by APT41 Hacker Group
Advanced persistent threat group APT41 launched an extended attack that successfully compromised a number of companies in the media and
cybersecuritynews.com
July 22, 2024 at 10:47 AM