APT10 — APT Profile
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
menuPass, Cicada, POTASSIUM, Stone Panda, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE, Menupass Team, happyyongzi, Cloud Hopper, ATK41, G0045, Granite Taurus, TA429, Purple Typhoon
IntelFusions coverage (3)
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24 · Nation-State
- menuPass (APT10) Deploys Cobalt Strike via Encrypted Executables and DKMC Bitmap Shellcode in Dual-Wave Attacks on Japanese Organizations 2026-02-16 · Nation-State
- APT10's Operation Cloud Hopper: How China's MSS Weaponized IT Service Providers for Global Espionage 2026-02-16 · Nation-State
Tools & malware
- Ecipekac malware
- Impacket tool
- P8RAT malware
- PlugX malware
- pwdump tool
- RedLeaves malware
- SodaMaster malware
- UPPERCUT malware
- win.mimikatz Credential Harvesting
Vendor research
- APT10 Targeting Japanese Corporations Using Updated TTPs Matsuda, A., Muhammad I
- APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat FireEye iSIGHT Intelligence
- POISON IVY: Assessing Damage and Extracting Intelligence FireEye
- APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign Kaspersky
- Operation Cloud Hopper PwC and BAE Systems
- Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign Symantec
- United States of America v. Zhu Hua and Zhang Shilong United States District Court Southern District of New York (USDC SDNY)
- United States v. Zhu Hua Indictment US District Court Southern District of New York
- APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat FireEye iSIGHT Intelligence
- POISON IVY: Assessing Damage and Extracting Intelligence FireEye
- Hogfish Redleaves Campaign Accenture Security
- APT10 Targeting Japanese Corporations Using Updated TTPs Matsuda, A., Muhammad I
- BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER Counter Threat Unit Research Team
- CrowdCasts Monthly: You Have an Adversary Problem Crowdstrike
- menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations Miller-Osborn, J. and Grunzweig, J.
Countries linked to this actor
- South Africa targets
- China origin
- Japan targets
- Philippines targets