APT10's Operation Cloud Hopper: How China's MSS Weaponized IT Service Providers for Global Espionage

The threat group known as APT10 — also tracked as Cloud Hopper, Red Apollo, Stone Panda, MenuPass, and POTASSIUM — has been identified as one of China's most strategically significant cyber espionage operations, according to the Council on Foreign Relations. The group is believed to operate under the Tianjin bureau of the Chinese Ministry of State Security (MSS).

Supply-Chain Espionage at Scale

Active since at least 2009, APT10's signature campaign — dubbed Operation Cloud Hopper — targeted managed IT service providers (MSPs) worldwide to gain downstream access to their clients' networks. By compromising a single MSP, the group could simultaneously infiltrate dozens of organizations across multiple sectors and countries, making it one of the most efficient espionage vectors ever documented.

Suspected victims span governments and private sector entities across Japan, the United States, United Kingdom, India, Canada, Brazil, South Africa, Australia, Thailand, South Korea, France, Switzerland, Sweden, Finland, Norway, and New Zealand — a truly global footprint reflecting China's broad intelligence collection priorities.

Tradecraft: Spear-Phishing to Persistent Access

APT10's tactics rely on a well-established playbook: spear-phishing campaigns deliver custom malware that establishes initial footholds, followed by lateral movement and persistent access within victim environments. The group is known for deploying custom backdoors and leveraging legitimate tools to maintain long-term presence while exfiltrating sensitive data, intellectual property, and confidential communications.

International Law Enforcement Response

In December 2018, the U.S. Department of Justice indicted two Chinese nationals associated with APT10's operations, directly linking the campaign to the MSS. The indictment, supported by allied governments including the UK and Australia, described sustained theft of intellectual property and confidential business data from organizations in aviation, space, satellite technology, manufacturing, pharmaceuticals, and other critical sectors. The case marked one of the most significant public attributions of Chinese state-sponsored cyber espionage to a specific intelligence bureau.

Read the full analysis on IntelFusions