[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBooNyV4Lqh0tV30i6_dpzrPeOjzsYuscVqN3000RCeg":3},{"article":4,"iocs":50,"watch_terms":61},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":34},"e62b7fd4-5dba-45ad-88da-0982f1b8e5e4","APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials","apt41-delivers-zero-detection-backdoor-to-harvest-cloud-credentials-b0bd30","The prolific China-backed threat group is targeting AWS, Google, Azure, and Alibaba cloud environments and using typosquatting to obscure C2 communication.","China-backed APT41 has been observed delivering a 'zero-detection' backdoor designed to harvest cloud credentials from major cloud providers including AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud. The group is using typosquatting techniques to obscure command-and-control communications and evade detection. This campaign represents a significant threat to cloud infrastructure security across multiple vendors.","APT41 deploys undetected backdoor targeting AWS, Google, Azure, and Alibaba cloud credentials.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcloud-security\u002Fapt41-zero-detection-backdoor-harvest-cloud-credentials","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt2e8cc931a1c1d4d4\u002F69dcc2c014d9c34775418603\u002Fchinaiptheft_Pixels_Hunter_shutterstock.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-04-13T15:08:12+00:00","2026-04-13T16:00:12.844611+00:00",9,[18,21,24,26,28],{"name":19,"type":20},"APT41","threat_actor",{"name":22,"type":23},"Amazon Web Services","vendor",{"name":25,"type":23},"Google Cloud",{"name":27,"type":23},"Microsoft Azure",{"name":29,"type":23},"Alibaba Cloud","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":30,"icon":11,"name":32,"slug":33},"Nation-state","nation-state",[35,40,45],{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":41},{"id":42,"icon":11,"name":43,"slug":44},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":46},{"id":47,"icon":11,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,54,58],{"type":39,"value":52,"context":53},"APT41 zero-detection backdoor","Undetected backdoor targeting cloud credential harvesting across AWS, Google Cloud, Azure, and Alibaba Cloud",{"type":55,"value":56,"context":57},"mitre_attack","T1078 - Valid Accounts","Credential harvesting and cloud account compromise",{"type":55,"value":59,"context":60},"T1583.001 - Acquire Infrastructure: Domains","Typosquatting domains for C2 communication obfuscation",[22,25,27]]