APT10, also known as menuPass, is a long-running China-nexus cyber-espionage threat actor publicly linked by the United States government to China’s Ministry of State Security, specifically the Tianjin State Security Bureau, and associated contractor activity. It is widely tracked under numerous aliases including Stone Panda, Cicada, Red Apollo, CVNX, POTASSIUM, HOGFISH, BRONZE RIVERSIDE, Purple Typhoon, and others. The group has conducted strategic espionage for well over a decade, with activity reported since at least the late 2000s. APT10 is best known for compromising managed service providers, IT service providers, and other trusted intermediaries in order to gain downstream access to customer environments at scale, a pattern exemplified by Operation Cloud Hopper. Beyond service-provider intrusions, the group has targeted government, defense, aerospace, healthcare, finance, maritime, biotechnology, energy, telecommunications, manufacturing, mining, legal, religious, NGO, pharmaceutical, and advanced technology organizations across Asia, Europe, and North America. Its objectives are consistently aligned with intelligence collection, theft of intellectual property, and acquisition of sensitive government and commercial information. The group commonly gains initial access through spearphishing attachments, malicious documents, and other user-execution lures, and has also been associated with exploitation of public-facing enterprise systems. APT10 frequently abuses trusted relationships and valid accounts after compromise. Observed tradecraft includes extensive use of PowerShell and Windows command shell, WMI, scheduled tasks, InstallUtil, DLL sideloading, credential dumping, Active Directory enumeration, remote services, and data staging prior to exfiltration. The actor has used native administrative and dual-use tools for reconnaissance and lateral movement, including exporting Active Directory data with csvde and using utilities such as certutil to decode staged payloads. Malware and tooling associated with APT10 across reporting include ANEL and related loaders, LODEINFO, NOOPDOOR, NOOPLDR, SOGU, HAYMAKER, SNUGRIDE, BUGJUICE, RedLeaves, PlugX, ChChes, SodaMaster, customized Quasar RAT variants, and other loaders and backdoors. The group has also demonstrated reflective and in-memory execution techniques, anti-forensics measures, and stealth-focused persistence. Some tooling overlaps with broader Chinese intrusion ecosystems, so malware presence alone is not sufficient for attribution. Reporting also describes a broader APT10 umbrella that includes related or descendant activity clusters. MirrorFace, also tracked as Earth Kasha, is assessed as a China-aligned subgroup or affiliated cluster within that umbrella and has focused heavily on Japanese targets while using ANEL, NOOPDOOR, customized AsyncRAT, DLL sideloading, and stealthy post-compromise tradecraft. More recent APT10-linked or umbrella-associated activity has shown continued adaptation, including abuse of cloud services, OAuth tokens, and legitimate remote-access or development services. Overall, APT10 remains one of the most significant Chinese espionage actors due to its longevity, global reach, service-provider targeting model, and sustained focus on strategic intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
32 malware families attributed to this actor across reporting.
27 additional families tracked in Mallory.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
The Microsoft Windows Netlogon Remote Protocol (MS-NRPC) reuses a known, static, zero-value initialization vector... Threat actors were seen combining the MobileIron CVE-2020-15505 vulnerability for initial access, then using the Netlogon vulnerability... A nation-state APT group has been observed exploiting this vulnerability.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The title of the lure was “2016年台灣總統選舉觀戰團 行程20160105.xls” which translates to “2016 Taiwan president election watching group schedule”. Once the spreadsheet is opened, CVE-2012-0158 is exploited and a file called 6EC5.tmp is dropped in the %TEMP% folder.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
6 more CVEs tied to this actor tracked in Mallory.
273 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with exploiting cloud environments, OAuth tokens, and legitimate services.
Referenced as the umbrella group to which MirrorFace is assessed to belong; the revival of the APT10-linked ANEL backdoor is cited as reinforcing that lineage.
Related The role of China in the Persian Gulf and potential cyberthreats: ... Tags: APT, APT10, China, Critical Infrastructure, Energy
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.