Hacking

APT41 Cyberattack on Gambling Sector: Sophisticated Tactics Unveiled

Published  ·  4 min read

The notorious Chinese nation-state actor APT41, also known as Brass Typhoon, Earth Baku, Wicked Panda, or Winnti, has been linked to a highly sophisticated cyber attack targeting the gambling and gaming industry.

"Over at least six months, the attackers secretly gathered sensitive information, including network configurations, user passwords, and secrets from the LSASS process," said Ido Naor, co-founder and CEO of Israeli cybersecurity firm Security Joes, in a statement shared with The Hacker News.

"During the intrusion, the attackers constantly adapted their toolset in response to the security team's actions. They observed the defenders' moves, adjusted their strategies, and modified their tools to bypass detection and maintain long-term access to the compromised network."

This multi-stage attack, which targeted one of Security Joes' clients, lasted nearly nine months this year. It overlaps with an intrusion campaign tracked by cybersecurity company Sophos under the name Operation Crimson Palace.

Naor noted that the company responded to the incident four months ago, stating, "These attacks are typically driven by state-sponsored decision makers. In this case, we are highly confident that APT41 was motivated by financial gain."

The campaign was meticulously crafted for stealth, using a wide range of techniques to bypass security software, collect critical information, and establish covert channels for sustained remote access.

Security Joes described APT41 as "highly skilled and methodical," highlighting the group's expertise in both espionage and financially motivated intrusions, such as ransomware and cryptocurrency mining. They are also known for their ability to poison supply chains, leading to intellectual property theft.

Although the exact initial access method remains unclear, evidence suggests it may have been spear-phishing emails, as there were no signs of active vulnerabilities in internet-facing applications or a supply chain compromise.

Once inside the target's infrastructure, the attackers launched a DCSync attack, attempting to steal password hashes from service and admin accounts to broaden their access. Using these credentials, they established persistence and maintained control of the network, focusing on administrative and developer accounts.

The attackers conducted thorough reconnaissance and post-exploitation activities, often modifying their toolset in response to defensive measures and escalating privileges to deploy additional malicious payloads. Among the techniques used were Phantom DLL Hijacking and the exploitation of the legitimate wmic.exe utility. They also abused administrative service accounts to trigger execution.

Hackers Target Gambling Sector

The second stage of the attack involved the deployment of a malicious DLL file named TSVIPSrv.dll over the SMB protocol. This payload established communication with a hardcoded command-and-control (C2) server.

"If the hardcoded C2 fails, the implant updates its C2 information by scraping GitHub users," said Security Joes. The malware parses HTML from GitHub, searching for capitalized words, extracting only the capital letters between A and P. These characters form an 8-character string that encodes the IP address of a new C2 server.

The initial connection with the C2 server allows the malware to profile the infected system and download additional malware through a socket connection.

After the attackers' activities were detected, they went silent for several weeks but returned with a new strategy, using heavily obfuscated JavaScript code hidden within a modified XSL file ("texttable.xsl") and executed via the LOLBIN wmic.exe.

Once launched, WMIC.exe executes the malicious JavaScript code from the XSL file, downloading a payload from the C2 server hosted at time.qnapntp[.]com. This payload fingerprints the machine and sends the information to the attacker, who likely targets only machines of specific interest.

Researchers noted that the malware was designed to focus on machines with IP addresses containing "10.20.22," targeting devices within the subnet 10.20.22[0-9].[0-255]. "By correlating this information with network logs and the IP addresses of the affected devices, we concluded that the attacker used this filter to ensure only devices within the VPN subnet were affected," said the researchers.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067