Initial Access
2 techniques·derived
The Cloud Hopper model — MSP management channels into client networks.
Operation Cloud Hopper — compromised managed service providers to reach their clients' networks, turning outsourced IT into a single point of failure.
ATTRIBUTED TOChina › Ministry of State Security (MSS) — Tianjin State Security Bureau › Huaying Haitai Science and Technology Development Co. (front company)
APT10 pioneered the managed service provider as an attack vector, and in doing so changed how defenders think about third-party risk.
Operation Cloud Hopper, documented by PwC and BAE Systems in 2017, described the group compromising MSPs and then moving through the legitimate management connections those providers maintain into client networks. The economics are brutally favourable: one MSP compromise yields access to dozens or hundreds of downstream organisations, and the intrusion arrives over trusted, expected administrative channels that security teams are unlikely to question.
The December 2018 U.S. indictment of Zhu Hua and Zhang Shilong tied the group to the Tianjin State Security Bureau through the front company Huaying Haitai Science and Technology Development Co. It also charged a separate long-running campaign against U.S. Navy personnel data and defence contractors, and was issued alongside coordinated statements from twelve allied governments — the broadest joint attribution against China at that time.
The group has remained active under sustained pressure, with continued campaigns against Japanese organisations and their overseas subsidiaries, and against telecommunications and government targets across Asia.
Down to the named unit where public evidence supports it.
Zhu Hua and Zhang Shilong were indicted by the U.S. Department of Justice in December 2018. The indictment identifies them as members of APT10 acting in association with the Tianjin State Security Bureau, operating through the front company Huaying Haitai. The charges cover Operation Cloud Hopper against MSPs in at least twelve countries and a separate campaign against U.S. Navy personnel records. Twelve allied governments issued concurring statements.
Attributing sources
10 designators across 10 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Custom implant developed from the open-source Trochilus RAT, used for durable MSP access.
Malpedia ↗Lightweight backdoor delivered by phishing, signed with stolen certificates.
Malpedia ↗Backdoor used against Japanese targets, with C2 over HTTP and staged plugin loading.
Implant used in continuing campaigns against Japanese media, government, and think tanks.
Shared, commodity & living-off-the-land
Shared Chinese backdoor delivered via DLL side-loading; heavily used in Cloud Hopper intrusions.
Malpedia ↗Open-source .NET RAT adopted in place of custom tooling to complicate attribution.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT10 | ||
|---|---|---|---|---|
| CVE-2021-26855KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Mar 2021 | ProxyLogon adopted following disclosure for Exchange access at enterprise targets.SRCESET ↗ |
| CVE-2018-13379KEVransomware | 9.8 | FortiOS SSL VPNFortinet | 1 Jun 2020 | FortiOS SSL VPN traversal used to obtain credentials for access to MSP and enterprise perimeters.SRCSymantec ↗ |
| CVE-2019-0604KEVransomware | 9.8 | Microsoft SharePointMicrosoft | 1 Jun 2019 | SharePoint deserialisation exploited to deploy web shells at government and enterprise targets.SRCSymantec ↗ |
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2018 | Equation Editor overflow in phishing documents against Japanese government and academic targets.SRCMandiant / FireEye ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
The Cloud Hopper model — MSP management channels into client networks.
2 techniques·derived
Malware signed with stolen certificates.
1 technique·derived
NTDS.
2 techniques·derived
Legitimate MSP administrative credentials for client access.
1 technique·derived
WinRAR staging of stolen material with password protection.
1 technique·derived
External Proxy.
1 technique·derived
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
The Cloud Hopper model — MSP management channels into client networks
Malware signed with stolen certificates
Legitimate MSP administrative credentials for client access
WinRAR staging of stolen material with password protection
Systematic compromise of managed service providers to reach their clients through legitimate management connections. One MSP compromise yielded access to dozens or hundreds of downstream organisations over trusted administrative channels.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both MSS-linked contractor operations with overlapping tooling, including ShadowPad and PlugX lineage implants.
Represents the post-2015 shift of PRC operations from PLA units to MSS provincial bureaus and contractors.
Shared PlugX lineage and DLL side-loading tradecraft.
Curated links to the reports that established what is known about this group.