Multiple reports linked the Chinese espionage group APT10—also tracked as MenuPass and Cicada—to long-running intrusions that used Poison Ivy, ChChes, and Sodamaster against governments, NGOs, telecoms, legal, pharmaceutical, academic, media, and managed service provider targets across Asia, Europe, and North America. FireEye previously clustered Poison Ivy activity into the menuPass, admin@338, and th3bug campaigns, while Palo Alto documented th3bug watering-hole attacks that delivered Poison Ivy through compromised websites and infrastructure tied together by shared command-and-control patterns. Trend Micro also reported that the Japan-focused ChessMaster espionage campaign overlapped with APT10 in targeting, malware packaging, infrastructure, and tradecraft, and Symantec later said Cicada/APT10 expanded operations through prolonged intrusions, in some cases beginning with Microsoft Exchange access and persisting for months.
Separate attribution research traced historical domain registrations, phishing metadata, social media accounts, and company records to alleged Tianjin-based operators including Gao Qiang, Zhang Shilong, and An Zhiqiang. Investigators said APT10-linked infrastructure such as chromeenter[.]com, js001.3322[.]org, xiaohong[.]org, and related domains connected to Tianjin email addresses, phone numbers, hostnames, and online personas including fisherxp, baobeilong, and @gbaike. The reporting argued that these overlaps tied real-world individuals and a Tianjin technology company to infrastructure associated with earlier Cloud Hopper and FireEye-tracked APT10 activity, strengthening claims that the group’s malware campaigns and domain operations were run by operators based in Tianjin, China.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
32 events from the most recent confirmed update back to the earliest known activity.
Symantec reports that the most recent activity it observed in the Cicada/APT10 campaign was in February 2022, with victims including government-related institutions, NGOs, and organizations in telecoms, legal, and pharmaceuticals.
Symantec says the earliest activity in a Cicada, also known as APT10, espionage campaign targeting organizations across Europe, Asia, and North America occurred in mid-2021.
Intrusion Truth states that a prior post on August 15, 2018 linked APT10 to the Tianjin bureau of China's Ministry of State Security.
Intrusion Truth published an analysis associating alleged APT10-linked individuals including Zheng Yanbin, Gao Qiang, and Zhang Shilong with the Tianjin companies Laoying Baichaun Instruments Equipment Co Ltd and Tianjin Huaying Haitai Science and Technology Development Co Ltd. The post argued these firms could represent corporate cover connected to APT10 activity and suggested possible state links, while stopping short of claiming definitive proof.
Intrusion Truth published an attribution analysis tying the email address zhengyanbin8@gmail.com and a cluster of domains, including infrastructure cited in commercial reporting, to an individual using the name Zheng Yanbin. The post concluded that Zheng Yanbin was associated with APT10 and likely helped purchase or manage command-and-control infrastructure used by the group.
Intrusion Truth says that on 2017-04-12 the registration information for xiaohong.org was changed to Domain Protection Services, making it effectively anonymous.
A FireEye blog post on APT10/MenuPass documented new tools and a global campaign as the latest manifestation of the longstanding threat.
Intrusion Truth reports that on 2016-01-06 the xiaohong.org registration was updated to add phone number +8615122188031 and change the email address to robin4700@foxmail.com.
Intrusion Truth says the baobeilong GitHub account forked both QuasarRAT and Trochilus in 2015, which it cites as evidence of interest in RATs associated with APT10 reporting.
Palo Alto Networks reports that on 2014-07-21 another Poison Ivy variant, setup.exe, was detected using C2 domain app.qohub.info and matching activity noted by Cisco TRAC.
On 2014-07-16, Palo Alto Networks detected a malicious file named PYvBte.jar on the compromised legitimate site uyghurweb.net; despite the JAR name, it was a Windows executable that downloaded and ran a Poison Ivy payload.
Palo Alto Networks says additional copies of diff.exe were collected on 2014-07-15 from multiple compromised sites, including uyghurweb.net, and used the same Poison Ivy infrastructure.
Palo Alto Networks reports that the first observed sample in a 2014 th3bug watering-hole campaign was seen on 2014-07-14, downloaded as diff.exe from npec.com.tw and using C2 domain diff.qohub.info.
FireEye's 2014 report introduced the Calamine toolset and said analysis of 194 Poison Ivy samples from 2008 to 2013 clustered activity into the admin@338, th3bug, and menuPass campaigns.
Intrusion Truth says chromeenter.com became WHOIS-protected in late June 2013 before being repossessed by GoDaddy and later named in FireEye reporting.
FireEye says Poison Ivy was used as the payload of an Internet Explorer zero-day in a strategic web compromise against visitors to a U.S. government website in May 2013.
Intrusion Truth says the registration for chromeenter.com was updated in April 2012, changing the registrant company to Tianjin Tiaoyiye Technology Co Limited and the registration email to gbaike@gmail.com.
Intrusion Truth states that weile3322b.3322.org resolved to 222.35.137.193 until 2012-02-15.
FireEye reports that the Nitro campaign remained active in 2012 and used a Java zero-day to deploy Poison Ivy.
FireEye states that Poison Ivy was used in the 2011 compromise of RSA involving theft of RSA SecurID-related data.
Intrusion Truth cites WHOIS data showing chromeenter.com was registered in April 2010 to Hogate Technology Co Limited.
Intrusion Truth says the domain weile3322b.3322.org, described as an APT10 domain in commercial reporting, resolved to 222.35.137.193 starting on 2010-01-23.
Intrusion Truth says an early 2010 phishing campaign distributing a Poison Ivy sample originated from masao_tomikawas@yahoo.com, with SMTP headers showing source IP 218.67.128.26 in Tianjin and submitting host fisherxp-pc.domain.
Intrusion Truth states that the @fisherxp Twitter account was registered in January 2010.
The xiaohong.org registration was updated on 2008-07-08 to include the fax number +865925163169.
Intrusion Truth reports that xiaohong.org registration details in 2007 listed Zhang Shilong as the registrant, with a Tianjin address, phone number, and the email atreexp@yahoo.com.cn.
Intrusion Truth says a 2006 article on atreex.cn, a Chinese-language hacking and IT security blog, linked to fisherx.com.
FireEye's report states that the Poison Ivy remote access trojan was first released in 2005.
Intrusion Truth published an analysis connecting An Zhiqiang and Tianjin Tianjiaoyiye Technology Co Ltd to chromeenter.com and other domain activity associated with APT10/MenuPass.
Intrusion Truth published an analysis linking the baobeilong persona, xiaohong.org, atreex.cn, and RAT-related GitHub activity to Zhang Shilong as a likely APT10 associate.
Intrusion Truth published an attribution analysis arguing that the fisherxp persona, Tianjin-linked infrastructure, and APT10-associated Poison Ivy activity pointed to Gao Qiang.
Trend Micro described the ChessMaster cyberespionage campaign targeting organizations in Japan and said it showed overlaps with APT10/menuPass in targeting, packers, infrastructure, and tradecraft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourceintrusiontruth.wordpress.com
Open sourceintrusiontruth.wordpress.com
Open sourceintrusiontruth.wordpress.com
Open sourceblog.trendmicro.com
Open sourcefireeye.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.