Special Bulletin
HHS OCIO HC3 TLP White Threat Briefing: APT41 and Recent Activity - September 22
Agenda
- Overview of APT41
- Targeting Operations
- Indictment
- Historical Targeting
- Threats to Healthcare
- Why Healthcare
- Recent Activity
- Popular Tools and Techniques
Overview
- Chinese State-Sponsored Threat Actor
- Members of APT41 have been actively tracked since 2012
- Also Known As: Double Dragon, Barium, Winnti, Wicked Panda, Wicked Spider, TG-2633, Bronze Atlas, Red Kelpie
- Has been tracked as two separate groups; dependent on operation
- History of targeting healthcare, high-tech, telecommunications, higher education, video games, travel, and news organizations
- Frequently likes to use the following:
- Spear phishing
- Water holes
- Supply chain attacks
- Backdoors
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:
John Riggi
National Advisor for Cybersecurity and Risk, AHA
jriggi@aha.org
(O) +1 202 626 2272
Key Resources
Related Resources
Guides and Reports
Advisory
Hospitals That Are Oracle Customers Urged to Take Immediate Action to Address Security Vulnerability
Issue Landing Page
Issue Landing Page
Guides and Reports