APT PRC State-Sponsored (MSS / Tianjin Bureau) Active since 2006

APT10

Cloud Hopper campaign targeting MSPs. Long-running espionage operations.

Scroll

APT10 is a PRC state-sponsored group operating on behalf of the Ministry of State Security Tianjin Bureau. The group is best known for Operation Cloud Hopper — a systematic campaign targeting managed service providers to gain access to their clients' networks. Two members were indicted by the US DOJ in 2018.

AttributeDetail
NamesAPT10 / Stone Panda / MenuPass
AttributionPRC State-Sponsored (MSS / Tianjin Bureau)
Active Since2006
Primary FocusCloud Hopper campaign targeting MSPs. Long-running espionage operations.

Overview

APT10 is a PRC state-sponsored group operating on behalf of the Ministry of State Security Tianjin Bureau. The group is best known for Operation Cloud Hopper — a systematic campaign targeting managed service providers to gain access to their clients' networks. Two members were indicted by the US DOJ in 2018.

Attribution

APT10 / Stone Panda / MenuPass is attributed to PRC State-Sponsored (MSS / Tianjin Bureau), active since at least 2006. Cloud Hopper campaign targeting MSPs. Long-running espionage operations.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1199Trusted RelationshipHigh
T1078Valid AccountsHigh
T1071Application Layer ProtocolHigh
T1048Exfiltration Over Alternative ProtocolHigh
T1059Command and Scripting InterpreterHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for APT10 activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting APT10 TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875