CN

APT10

High ConfidenceHigh Threat

Stone Panda • MenuPass • POTASSIUM • Red Apollo • CVNX • Cicada

APT10, tracked as Stone Panda or MenuPass Group, is a sophisticated Chinese cyber espionage unit linked to the Ministry of State Security (MSS). The group gained notoriety for Operation Cloud Hopper (2014-2017), a global campaign targeting managed service providers (MSPs) to gain access to their clients' networks. This supply chain attack methodology allowed APT10 to compromise organizations across healthcare, aerospace, defense, and technology sectors in at least 12 countries. In 2018, the U.S. Department of Justice indicted two Chinese nationals associated with the group. APT10 continues to evolve their tradecraft, employing custom malware families like QuasarRAT, PlugX, and Poison Ivy.

Origin: China
Sponsor: MSS (Ministry of State Security) - Tianjin Bureau
Active: 2006 - Present
Victims: 500+ organizations
Advanced
Active
EspionageIntellectual Property Theft
Risk Assessment
81
Composite Risk Score
High Risk
ARCS Compliance85
Escalation Risk80
Grievance Index75
Infrastructure Impact82
History & Evolution

APT10, tracked as Stone Panda or MenuPass Group, is a sophisticated Chinese cyber espionage unit linked to the Ministry of State Security (MSS). The group gained notoriety for Operation Cloud Hopper (2014-2017), a global campaign targeting managed service providers (MSPs) to gain access to their clients' networks. This supply chain attack methodology allowed APT10 to compromise organizations across healthcare, aerospace, defense, and technology sectors in at least 12 countries. In 2018, the U.S. Department of Justice indicted two Chinese nationals associated with the group. APT10 continues to evolve their tradecraft, employing custom malware families like QuasarRAT, PlugX, and Poison Ivy.

Targeting

Target Sectors

TechnologyManufacturingHealthcareAerospaceGovernmentMSPs

Target Regions

United StatesJapanEuropeGlobal
Attribution & Affiliations

Attributed to MSS (Ministry of State Security) - Tianjin Bureau (China). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Highly
Targeting
Highly
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

APT10 is expected to continue operations targeting Technology sectors.

Timeline of Key Events
2006
Major

First observed activity of APT10

2024
Moderate

Continued active operations