intel.breakglass.tech APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
Article Content
- •APT41's new ELF backdoor targets major cloud platforms with zero detections on VirusTotal.
- •The malware uses SMTP port 25 for covert command-and-control communication.
- •Typosquatting techniques complicate tracking and detection of APT41's activities.
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba Cloud. The backdoor operates via SMTP port 25 for command-and-control communication, making it difficult to detect with conventional tools. This malware harvests cloud provider credentials and metadata, posing a significant risk to organizations with broad permissions. The backdoor has zero detections on VirusTotal, indicating its stealthy nature. APT41 has also employed typosquatting techniques, registering domains that mimic legitimate services to obscure its activities. The campaign represents a notable evolution in APT41's operational tactics, focusing on cloud environments rather than traditional endpoints. The group has a history of state-sponsored espionage and cybercrime, with previous indictments failing to deter its operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track APT41, Pwnlnx and Alibaba Cloud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE, and EPA…