Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
APT41
Also tracked as BARIUM · Brass Typhoon · Wicked Panda
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. [APT41](https://attack.mitre.org/groups/G0096) overlaps at least partially with public reporting on groups including BARIUM and [Winnti Group](https://attack.mitre.org/groups/G0044).(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 2021)
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0096- ATT&CK record
- G0096
- Record version
- 4.2
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 04
- Mapped events
- 13
- Evidence gates
- 15
- Defensive analytics
- 06
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps APT41 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/3
Failed gates
0/3
Pending
3/3
Coverage gaps
0/3
- 1
- 2
- 3
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
PATH 01
T1070.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT41 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E14 to E28
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E1413:00Build interpositionFile integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
BLD-WIN-03
- E1615:00Build interpositionFile integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
BLD-WIN-03
- E2824:30InvestigationFile integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
BLD-WIN-03
PATH 02
T1071.001
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT41 to T1071.001 Application Layer Protocol: Web Protocols. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E23 to E23
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E2322:00Downstream signalEgress proxy
Egress proxy records a first-seen destination from the build tier
One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.
BLD-WIN-03
PATH 03
T1071.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT41 to T1071.004 Application Layer Protocol: DNS. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E04 to E04
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0403:00ReconnaissanceDNS resolver
Resolver log — reserved example domain queried
A single lookup for updates.example.net appears in the range resolver log. In this fixture it is benign-looking and unremarkable in isolation.
DEV-JUMP-07
PATH 04
T1195.002
Compromise Software Supply Chain
Initial Access · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT41 to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E08 to E29
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0807:00Build accessCI orchestrator
The adversary waits for a legitimate build
Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.
- E1110:00Build interpositionEndpoint telemetry
The helper observes the compiler invocation
The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.
BLD-WIN-03
- E11A10:30Build interpositionCI orchestrator
Selectivity check — correct product and expected source version
Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.
BLD-WIN-03
- E1514:00Build interpositionCI orchestrator
Produced binary hash differs from the reproducible reference
Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.
BLD-WIN-03
- E1716:00Trusted releaseCI orchestrator
Trusted release — the ordinary workflow accepts the artifact
Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.
- E2019:00Trusted releaseRelease system
Provenance record lacks the compile-input attestation
The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.
- E2422:30Downstream signalEndpoint telemetry
Marker string observed in the released artifact inventory
Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.
- E2925:00InvestigationRelease system
Provenance gap documented as the failed boundary
Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.