In August 2019, FireEye released the “Double Dragon” report on our newest graduated threat group: APT41. A China-nexus dual espionage and financially-focused group, APT41 targets industries such as gaming, healthcare, high-tech, higher education, telecommunications, and travel services. This blog post is about the sophisticated passive backdoor we track as LOWKEY, mentioned in the APT41 report, and associated with ESETs recent Winnti Group related blog https://www.welivesecurity.com/2019/10/14/connecting-dots-exposing-arsenal-methods-winnti/ .

REFERENCES:
https://www.fireeye.com/blog/threat-research/2019/10/lowkey-hunting-for-the-missing-volume-serial-id.html
https://www.welivesecurity.com/2019/10/14/connecting-dots-exposing-arsenal-methods-winnti/
GROUP:
ADVERSARY: