Adversary-emulation profile for APT41 (Double Dragon / Wicked Panda / BARIUM / Brass Typhoon, ATT&CK G0096), a Chinese dual-mandate espionage-and-cybercrime actor.
49
53%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt41-double-dragon/SKILL.mdAPT41 (MITRE ATT&CK G0096; also tracked as Double Dragon, Wicked Panda, Winnti, BARIUM, and Microsoft's Brass Typhoon) is a prolific Chinese threat actor unique for running state-sponsored cyber-espionage in parallel with financially motivated cybercrime — often reusing the same non-public malware for both missions. First publicly profiled by FireEye/Mandiant in August 2019, the group has been active since at least 2012, beginning in the video-game economy (virtual-currency theft, ransomware, code-signing certificate theft) and expanding into wide-ranging espionage. APT41 is best known for software supply-chain compromises (poisoning legitimately signed installers), rapid weaponization of newly disclosed vulnerabilities, abuse of stolen code-signing certificates, and a deep, modular toolset spanning Windows and Linux. This profile maps APT41's documented TTPs to ATT&CK so Decepticon can emulate them under authorized scope and the blue cell can anticipate detection.
cmd.exe /c on remote hosts), Unix shell for surveys, and JScript web shells./etc/rc.d/init.d) for rootkit loading.StorSyncSvc; "Windows Defend" service for DUSTPAN).NT AUTHORITY\SYSTEM.LD_PRELOAD hijacking on Linux.reg save, shadow copies), and NTDS (ntdsutil → ntds.dit).net enumeration of local and domain admins.net share enumeration.systeminfo/net config, ipconfig/MAC, netstat/HIGHNOON RDP-session enumeration, whoami.Authorized use only: Execute these techniques solely within the documented engagement scope, rules of engagement, and authorization window. Stay inside approved target ranges and obtain explicit sign-off before any destructive or impact-stage action.
Map APT41's signature behaviors to Decepticon's own capabilities:
certutil/BITSAdmin (bash/Windows command skills) to pull a stager, then load via rundll32 / DLL side-loading.ntdsutil ntds.dit, then perform Pass-the-Hash exactly as APT41 does with Mimikatz/Impacket-equivalent tooling.net/whoami/systeminfo/netstat LOLBin survey via the bash/command skills and AD enumeration; add domain-trust discovery before pivoting.Recommended emulation chain (DUST campaign analog): web shell → certutil/DUSTPAN-style dropper → side-loaded loader → Sliver BEACON over HTTPS/CDN → credential dump + PtH → SMB/WMI lateral movement → DB collection → DNS/cloud exfil.
reg save of SAM/SYSTEM, shadow-copy creation, and ntdsutil/NTDS access on DCs. Enable Credential Guard and LSASS protection.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.