Cyberwarfare

Chinese Hacking Group APT41 Infiltrates Global Shipping and Tech Sectors, Mandiant Warns

Chinese government-backed hacking team caught breaking into organizations in shipping, logistics and automotive sectors in Europe and Asia.

Chinese government-backed hacking team caught breaking into organizations in shipping, logistics and automotive sectors in Europe and Asia.

Researchers at Mandiant are flagging a significant resurgence in malware attacks by APT41, a prolific Chinese government-backed hacking team caught breaking into organizations in the shipping, logistics, technology, and automotive sectors in Europe and Asia.

Mandiant said the bulk of the compromised organizations are located in the United Kingdom, Italy, Spain, Turkey, Taiwan, and Thailand and warned that APT41 has managed to infiltrate these organizations and maintain prolonged, unauthorized access since at least 2023. 

In a technical report documenting its findings, Mandiant said APT41 (also tracked as Barium, Wicked Panda and Winnti) is also conducting reconnaissance activities against similar organizations in countries like Singapore, indicating a potential expansion of targeting.

The group is known for its dual-role operations, conducting both state-sponsored espionage and financially motivated intrusions.  Espionage targets include healthcare, high-tech, telecommunications, and other economically significant sectors. 

Notably, APT41 has previously used software supply chain compromises, UEFI firmware implants, and stolen digital certificates in its operations.

In the latest observed attacks, Mandiant said APT 41 used web shells on Tomcat Apache Manager servers to execute a dropper that then deployed a backdoor for command-and-control communications. 

Advertisement. Scroll to continue reading.

The group later used a multi-stage plugin framework called DUSTTRAP that leaves minimal forensics traces after the hackers conduct “hands-on keyboard” activities and a command-line utility to export stolen data from Oracle databases. 

“The decrypted payload was designed to establish communication channels with either APT41-controlled infrastructure for command and control or, in some instances, with a compromised Google Workspace account, further blending its malicious activities with legitimate traffic,” Mandiant researchers explained.

The company published indicators of compromise and forensics data to help organizations hunt for signs of APT41 infections.

Over the years, APT41 has been observed hacking into thousands of organizations worldwide, including software and video gaming companies, governments, universities, think tanks, non-profit entities, and pro-democracy politicians and activists in Hong Kong.

APT41’s activity spans over more than a decade, with victims located in the United States, Australia, Brazil, Chile, Hong Kong, India, Indonesia, Japan, Malaysia, Pakistan, Singapore, South Korea, Taiwan, Thailand, and Vietnam.

The U.S. Department of Justice has charged Chinese nationals Zhang Haoran and Tan Dailin, and Jiang Lizhi, Qian Chuan, and Fu Qiang and linked them to APT41 hacking activities.

Related: Chinese APT Uses ‘Stack Rumbling’ Technique to Kill Security Software

Related: Details Emerge on Operations, Members of China’s APT41 Hackers

Related: China’s APT41 Exploited Citrix, Cisco, ManageEngine Flaws

Related: Chinese APT41 CaughtUsing ‘MoonBounce’ UEFI Firmware Implant

Related Content

Government

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.

Vulnerabilities

CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching.

Nation-State

Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.

Malware & Threats

Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.

Nation-State

The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was. 

Malware & Threats

Dubbed GopherWhisper, the group relies on multiple Go-based backdoors alongside custom loaders and injectors.

Nation-State

The state-sponsored threat actor deployed kernel implants and passive backdoors enabling long-term, high-level espionage.

Cybercrime

The latest M-Trends report is based on insights from over 500,000 hours of Mandiant incident response investigations in 2025.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version