APT41 is remarkable among nation-state threat actors for doing something that most state-sponsored groups do not: conducting both government-directed espionage and financially motivated cybercrime, apparently simultaneously, using the same operators and infrastructure. Mandiant, which tracks the group and coined the name "Double Dragon" to reflect this duality, describes APT41 as a Chinese state-nexus threat actor that has conducted operations aligned with Chinese government intelligence priorities while also pursuing personal financial gain - including theft of gaming company source code and virtual currency, pharmaceutical company intellectual property, and semiconductor trade secrets.
The US Department of Justice indicted seven APT41 members in September 2020, providing the most detailed public accounting of the group's activities. The indictments named members of two front companies - Chengdu 404 Network Technology and Guangdong Bozhi Technology - and described intrusions into over 100 companies in the US and abroad, including software developers, telecommunications companies, universities, foreign governments, and pro-democracy activists in Hong Kong. The breadth of targets and techniques described in the indictments made APT41 the most prolific Chinese threat actor documented in public US government sources.
State Espionage and Personal Enrichment
Most state-sponsored cyber actors are constrained by their government employers to conduct operations aligned with national interests. The intelligence services of Russia, China, Iran, and North Korea task their cyber operators with stealing secrets, conducting sabotage, or influencing foreign political processes. Financial crime is generally not on the menu - and when it occurs (as with North Korea's Lazarus Group), it is explicitly state-directed to fund the regime.
APT41 appears to be different. Evidence from the indictments and from incident response investigations suggests some operators conduct state-directed espionage as their primary job while running financially motivated cybercrime operations on the side - or possibly with tacit government approval as a compensation supplement. The financial operations included theft of millions of dollars' worth of in-game currency from video game companies (Blizzard, Riot Games, and others), theft of gaming company source code (which could be used to create unfair advantages or clone games), and cryptocurrency theft.
The motivation structure is unusual and has been the subject of significant analysis. One theory is that the Chinese government tolerates or encourages side-income activities by cyber operators as a way of attracting talented individuals who might otherwise earn more in legitimate private sector roles. Another theory is that the espionage and financial operations are actually separate groups with overlapping infrastructure that have been conflated into a single APT designation. The available evidence supports the former theory: individual named defendants in the DOJ indictments appear connected to both espionage and financial operations.
Supply Chain Operations
APT41 has conducted multiple supply chain compromise operations - compromising software vendors to deliver malware through legitimate software update mechanisms to downstream customers. The approach provides access to organizations that would otherwise be extremely difficult to penetrate directly, because the malicious code arrives via a trusted software channel.
The most documented APT41 supply chain operation compromised ASUS's Live Update software between June 2018 and November 2018, delivering a backdoor to approximately 1 million ASUS users. However, analysis showed the backdoor only activated on a small subset of target machines - those whose MAC addresses matched a specific hardcoded list. The operation was designed for surgical access to specific targets, using the million-machine infection as cover. Kaspersky researchers who analyzed the attack (known as "ShadowHammer") found approximately 600 MAC addresses in the target list, suggesting specific individuals or organizations were the real targets.
Other confirmed or suspected APT41 supply chain operations targeted video game update mechanisms (multiple gaming companies), CCleaner (a widely-used PC cleaning utility, 2017, resulting in 2.27 million infected systems), and Asian government software. The SHADOWPAD backdoor has been found in supply chain compromises affecting multiple software vendors including Netsarang (HR management software used by large enterprises in Asia), MongooseIM, and others.
The 2020 Indictments
The September 2020 DOJ indictments charged five Chinese nationals: Zhang Haoran, Tan Dailin, Jiang Lizhi, Qian Chuan, and Fu Qiang - along with two Malaysian nationals who assisted with cashing out. The five Chinese nationals remained in China and were not arrested. The two Malaysians, Wong Ong Hua and Weng Ming Shiung, were arrested in Malaysia and faced extradition proceedings, though outcomes of those proceedings were not publicly announced as of mid-2024.
The indictments described intrusions into more than 100 companies in the US and abroad, covering: software development companies, computer hardware manufacturers, telecommunications providers, social media companies, video game companies, universities, think tanks, foreign governments, and pro-democracy politicians in Hong Kong. The pro-democracy targeting reflected the espionage mission; the video game and software targeting reflected the financial operations; the telecommunications and government targeting reflected both.
The breadth of the indictment - 100+ victim organizations, 7 defendants, activities spanning from 2014 to 2020 - reflected how much the DOJ and FBI had learned about the group through years of investigation. It was the most comprehensive public accounting of a Chinese APT group's activities ever released, and it provided the security research community with significant additional information for tracking and attributing APT41 intrusions.