Home/Threat Actor/APT10
Threat Actor

APT10

apt10_stonepanda · china · active since 2006

APT10 (menuPass / Stone Panda / Cicada / POTASSIUM / Red Apollo / CVNX / HOGFISH / BRONZE RIVERSIDE / Cloud Hopper / Granite Taurus / Purple Typhoon / G0045) is a Chinese state-sponsored cyber-espionage actor attributed to the People's Republic of China Ministry of State Security, Tianjin State Security Bureau, operating via the MSS contractor model through the front company Huaying Haitai Science and Technology Development Company, formally established by the December 2018 US DOJ indictment of Zhu Hua and Zhang Shilong and a coordinated seven-government attribution statement.

active since at least 2006, APT10 is the architect of the managed service provider supply-chain compromise model exposed in PwC/BAE Systems/UK NCSC's April 2017 'Operation Cloud Hopper' report, a strategic innovation that turned MSP-customer trust relationships into an industrial-scale attack vector.

the group has sustained multi-decade targeting of aerospace, defense, satellite technology, maritime, energy, pharmaceutical, government, and managed-IT targets globally with persistent emphasis on Japan, and has continuously evolved tradecraft from PlugX/Poison Ivy era - ChChes/Anel/RedLeaves - the A41APT Ecipekac/SodaMaster/ P8RAT multi-layered-loader campaign (Kaspersky 2021) - the sustained LODEINFO Japan-targeting campaign - the modern NOOPDOOR backdoor with DNS-over-HTTPS C2, while DLL side- loading via legitimately-signed executables remains its defining technical fingerprint.

china confidence: high 32 aliases MITRE ATT&CK G0045 ↗

Profile

APT10 is a Chinese state-sponsored cyber-espionage actor attributed to the People's Republic of China Ministry of State Security (MSS), Tianjin State Security Bureau (TSSB), operating via the characteristic MSS contractor model. The December 17, 2018 US Department of Justice indictment of Zhu Hua and Zhang Shilong, alleged APT10 operators working for the Chinese technology front company Huaying Haitai Science and Technology Development Company under TSSB direction, formally established this attribution and was unprecedented in its scope: a coordinated multi-government attribution statement issued the same day by the US, UK, Australia, Canada, New Zealand, Japan, and Germany. The group has been active since at least 2006, making it one of the longest-running Chinese state cyber- espionage clusters in public reporting.

APT10's defining strategic innovation is systematic targeting of managed service providers (MSPs) and cloud service providers to gain trusted-relationship access to downstream client environments, the Operation Cloud Hopper model disclosed by PwC, BAE Systems, and UK NCSC in April 2017. By compromising a single IT outsourcing provider, APT10 could access the networks of dozens or hundreds of downstream client organizations, turning the MSP-customer trust relationship into an industrial-scale attack vector. This pattern triggered global MSP security reviews and the development of dedicated MITRE ATT&CK coverage for T1199 (Trusted Relationship) compromise.

Targeting heavily emphasizes Japan, the most consistent regional focus across two decades of activity, but extends globally across aerospace, defense, satellite technology, maritime, oil and gas, mining, manufacturing, pharmaceutical, biotechnology, financial services, telecommunications, and government targets in the US, UK, Europe, Canada, Australia, India, and elsewhere. The 2018 DOJ indictment specifically documented compromises of NASA Jet Propulsion Laboratory and Goddard Space Flight Center, and the theft of personal data on more than 100,000 US Navy personnel. Technical tradecraft hallmarks: (a) DLL side-loading as the defining loading technique (T1574.

002), often via legitimately- signed executables; (b) multi-stage loaders evolving from PlugX/Poison Ivy era
  • ChChes/Anel.
  • RedLeaves.
  • Quasar/UPPERCUT.
  • Ecipekac/SodaMaster/P8RAT (A41APT)
  • LODEINFO.
  • NOOPDOOR/NOOPLDR with DNS-over-HTTPS C2; (c) sustained use of China Chopper and TwoFace web shells; (d) credential harvesting via Mimikatz, LaZagne, pwdump; (e) BloodHound/SharpHound for AD enumeration; (f) Cobalt Strike beacons for post-exploitation; (g) RAR-archived password-protected exfiltration. Operations follow Beijing business hours. The 2022 Secureworks disclosure of BRONZE STARLIGHT ransomware activity using HUI Loader (an APT10-cluster tool) suggests occasional ransomware deployment as cover for espionage, shortening attacker dwell-time visibility and providing plausible alternative attribution. APT10 / TA410 cluster boundaries remain debated: ESET treats TA410 as a separate umbrella with three internal sub-teams (FlowingFrog, LookingFrog, JollyFrog), while MITRE notes the overlap with APT10 without formal merger.

Aliases

32
apt10menupassmenupass teammenupass groupcicadapotassiumstone pandastonepandared apollocvnxcnvxhogfishbronze riversidecloud hoppercloudhopperoperation cloud hoppergranite tauruspurple typhoonatk41ta410ta429happyyongzichessmastermss tianjinmss tianjin state security bureautianjin state security bureautssbhuaying haitaihuaying haitai science and technologyg0045apt 10apt-10

Notable Campaigns

10
2024NOOPDOOR / NOOPLDR Targeting Japanese Organizations (2024)
2022BRONZE STARLIGHT Ransomware Overlap (Secureworks June 2022)
2021-2024TA410 / FlowingFrog / LookingFrog / JollyFrog Sub-Clusters (2021-2024)
2020-2021Cicada (Symantec), Japan-Linked Organizations Targeted (Nov 2020)
2019-2026LODEINFO Long-Running Japan Targeting (2019-present)
2019-2021A41APT Campaign, Long-Running Multi-Loader Espionage (2019-2021)
2018US DOJ Indictment of Zhu Hua and Zhang Shilong (December 17, 2018)
2017ChessMaster Campaign (Trend Micro 2017)
2014-2017Operation Cloud Hopper (PwC/BAE Systems April 2017)
2006-2014Early Japanese Target Campaigns (2006-2014)

Attribution & Reporting

Attributed by
US Department of JusticeFBICISANSAUS Department of StateUS Department of TreasuryUK NCSCUK National Cyber Security CentreFive EyesPwCBAE SystemsMandiantFireEyeMicrosoftCrowdStrikeSymantec / BroadcomCisco TalosTrend MicroKaspersky GReATAccenture SecuritySecureworks Counter Threat UnitJPCERT/CCMacnica NetworksRecorded FutureInsikt GroupSentinelOne
Key reporting
reportPwC and BAE Systems / UK NCSC: Operation Cloud Hopper (April 2017)
reportPwC and BAE Systems: Operation Cloud Hopper, Technical Annex (April 2017)
reportFireEye iSIGHT Intelligence: APT10 (MenuPass Group), New Tools, Global Campaign (April 2017)
reportUS DOJ Indictment: USA v. Zhu Hua and Zhang Shilong (December 17, 2018)
reportFBI Wanted Notices: Zhu Hua and Zhang Shilong
reportUK NCSC: UK and Allies Reveal Global Scale of Chinese Cyber Campaign (December 2018)
reportAccenture Security: HOGFISH RedLeaves Campaign (April 2018)
reportSymantec: Cicada, Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign (November 2020)
reportKaspersky GReAT: APT10, Sophisticated Multi-Layered Loader Ecipekac Discovered in A41APT Campaign (March 2021)
reportSecureworks CTU: BRONZE STARLIGHT Ransomware Operations Use HUI Loader (June 2022)
reportJPCERT/CC: LODEINFO Activity Alert (Multiple, 2020-2024)
reportJPCERT/CC: NOOPDOOR Targeting Japanese Organizations (2024)
reportTrend Micro: ChessMaster Cyber-Espionage Campaign (2017)
reportTrend Micro: APT10 Targeting Japanese Corporations Using Updated TTPs (September 2018)
reportTrend Micro: LODEINFO Evolves (August 2024)
reportESET: A Lookback Under the TA410 Umbrella (April 2022)
reportProofpoint: LookBack Malware Targets United States Utilities Sector
reportMacnica Networks: APT10 Operations Targeting Japan (2018)
reportCouncil on Foreign Relations: APT 10 Cyber Operations Tracker
reportEuRepoC: APT Profile, APT 10

Operational

State sponsor

People's Republic of China Ministry of State Security (MSS), Tianjin State Security Bureau (TSSB). Operates via MSS contractor model, individual operators known to have worked for Chinese technology front company Huaying Haitai Science and Technology Development Company, per the December 2018 US DOJ indictment of Zhu Hua and Zhang Shilong.

Motivations
espionage, intelligence_gathering, intellectual_property_theft, industrial_espionage, supply_chain_compromise, economic_advantage, five_year_plan_alignment, regional_dominance_in_asia, strategic_industries_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin