Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

⚠️ CONFIDENCE NOTE: This campaign report is sourced from secondary threat intelligence; primary corroboration from CISA or authoritative vendor has not been confirmed. Treat with elevated scrutiny and monitor for authoritative validation.

APT41 (Double Dragon), a Chinese state-sponsored threat group, is reported to be operating a credential harvesting campaign targeting organizations using AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud. The group is deploying a backdoor that disguises command-and-control traffic using typosquatted domains mimicking legitimate cloud service endpoints, making detection at the network layer difficult. If confirmed, this campaign represents a sustained intelligence collection operation with potential to compromise cloud-hosted data, identities, and downstream enterprise systems across all major cloud providers.

Author

Tech Jacks Solutions