APT-41 (also tracked as Winnti, Barium, and Double Dragon) has been observed conducting a targeted campaign against financial sector infrastructure, with a focus on SWIFT messaging systems and algorithmic trading platforms.
Initial access is achieved via spear-phishing targeting IT administrators, followed by lateral movement using living-off-the-land techniques. The group's ultimate objective appears to be financial data exfiltration and potential market manipulation.
