TA410 is a China-nexus cyberespionage umbrella group loosely linked to APT10 and also referred to as Witchetty. Reporting describes TA410 as a distinct, mature threat actor conducting sustained operations against geopolitically sensitive targets. Known targeting includes the U.S. utilities sector, Middle Eastern governments, and Japanese organizations. Proofpoint attributed both the LookBack and FlowCloud campaigns observed between July and November 2019 to TA410 based on shared attachment macros, malware installation techniques, and overlapping delivery infrastructure. In those campaigns, TA410 targeted U.S. utility providers with phishing lures themed around energy training and certification, including impersonation of organizations such as ASCE. FlowCloud was described as a modular C++ remote access trojan providing broad system access, including files, processes, services, screen, keyboard, mouse, clipboard, and data exfiltration over command and control. TA410 shifted FlowCloud delivery from PE attachments to malicious Word documents with macros resembling LookBack delivery, including handling .pem files, renaming payloads, and certutil abuse. Proofpoint noted overlaps with TA429/APT10 tactics and infrastructure, including shared macro patterns and a Quasar RAT-related URL, but did not attribute the activity to APT10 and assessed the overlaps may have been false-flag reuse. TA410 has also been associated with FlowCloud activity targeting Japanese organizations. Cisco Talos further noted that ESET reported an XLL stage in TA410 activity in 2020, and cited a TA410-related process injection DLL, onkeytoken_keb.dll, that exports xlAutoOpen while triggering injection via the exported function OnKeyT_ContextInit. Talos described TA410 as a cyberespionage umbrella group loosely linked to APT10. Additional reporting cited an artifact, the file path C:\Users\hellokety.ini, in HUI Loader-related activity that had previously been reported in operations linked to APT10 and TA410. However, separate reporting emphasized attribution uncertainty in broader China-aligned activity because Chinese threat groups frequently share tooling and infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus espionage group discussed due to shared HUI Loader artifacts and possible overlap or misattribution with related operations.
TA410 is a China-nexus threat actor known for targeting government and public sector organizations, especially in Japan, using custom malware and supply chain attacks.
Cyberespionage activity leveraging an XLL stage within a broader toolkit; includes a process-injection DLL component referenced in the report.
Cyber-espionage activity cluster; in this context, incorporates an XLL-related component within a broader toolkit, including a process-injection DLL that includes an xlAutoOpen export (though execution is triggered via another export).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.