Skip to content
ChinaState-SponsoredActiveMITRE G0045Malpedia ↗

APT10

Operation Cloud Hopper — compromised managed service providers to reach their clients' networks, turning outsourced IT into a single point of failure.

ATTRIBUTED TOChina › Ministry of State Security (MSS) — Tianjin State Security Bureau › Huaying Haitai Science and Technology Development Co. (front company)

Open MITRE Navigator layer ↗Download profile JSON
Active
2006–present
Motivation
Espionage, IP Theft
Aliases
10
Exploited CVEs
4
ATT&CK techniques
10
Cited sources
9

Overview

APT10 pioneered the managed service provider as an attack vector, and in doing so changed how defenders think about third-party risk.

Operation Cloud Hopper, documented by PwC and BAE Systems in 2017, described the group compromising MSPs and then moving through the legitimate management connections those providers maintain into client networks. The economics are brutally favourable: one MSP compromise yields access to dozens or hundreds of downstream organisations, and the intrusion arrives over trusted, expected administrative channels that security teams are unlikely to question.

The December 2018 U.S. indictment of Zhu Hua and Zhang Shilong tied the group to the Tianjin State Security Bureau through the front company Huaying Haitai Science and Technology Development Co. It also charged a separate long-running campaign against U.S. Navy personnel data and defence contractors, and was issued alongside coordinated statements from twelve allied governments — the broadest joint attribution against China at that time.

The group has remained active under sustained pressure, with continued campaigns against Japanese organisations and their overseas subsidiaries, and against telecommunications and government targets across Asia.

Attribution

Down to the named unit where public evidence supports it.

ChinaMinistry of State Security (MSS) — Tianjin State Security BureauHuaying Haitai Science and Technology Development Co. (front company)Confirmed

Zhu Hua and Zhang Shilong were indicted by the U.S. Department of Justice in December 2018. The indictment identifies them as members of APT10 acting in association with the Tianjin State Security Bureau, operating through the front company Huaying Haitai. The charges cover Operation Cloud Hopper against MSPs in at least twelve countries and a separate campaign against U.S. Navy personnel records. Twelve allied governments issued concurring statements.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 10 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • menuPass

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

CrowdStrike

index ↗
  • Stone Panda

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT10

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • BRONZE RIVERSIDE

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • RedApollo

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Kaspersky GReAT

index ↗
  • CVNX

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • ChessmasterpartialTrend Micro's campaign-specific designator

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Proofpoint

index ↗
  • TA429

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

Symantec (Broadcom)

index ↗
  • Cicada

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • APT10 / Tianjin State Security Bureau

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

JapanUnited StatesUnited KingdomFranceIndiaSouth KoreaCanadaAustraliaNorwaySweden

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

RedLeavesbackdoor

Custom implant developed from the open-source Trochilus RAT, used for durable MSP access.

Malpedia ↗
ChChesbackdoor

Lightweight backdoor delivered by phishing, signed with stolen certificates.

Malpedia ↗
UPPERCUT / ANELbackdoor

Backdoor used against Japanese targets, with C2 over HTTP and staged plugin loading.

LODEINFObackdoor

Implant used in continuing campaigns against Japanese media, government, and think tanks.

Shared, commodity & living-off-the-land

PlugXbackdoor

Shared Chinese backdoor delivered via DLL side-loading; heavily used in Cloud Hopper intrusions.

Malpedia ↗
QuasarRATbackdoor

Open-source .NET RAT adopted in place of custom tooling to complicate attribution.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT10
CVE-2021-26855KEVransomware9.81 Mar 2021ProxyLogon adopted following disclosure for Exchange access at enterprise targets.SRCESET
CVE-2018-13379KEVransomware9.81 Jun 2020FortiOS SSL VPN traversal used to obtain credentials for access to MSP and enterprise perimeters.SRCSymantec
CVE-2019-0604KEVransomware9.81 Jun 2019SharePoint deserialisation exploited to deploy web shells at government and enterprise targets.SRCSymantec
CVE-2017-11882KEVransomware7.81 Jan 2018Equation Editor overflow in phishing documents against Japanese government and academic targets.SRCMandiant / FireEye

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 7 tactics · 4 with actor-specific notes

Initial Access

2

Lateral Movement

2

Collection

1

Command and Control

1

Campaign timeline

  1. landmark

    Operation Cloud Hopper

    Systematic compromise of managed service providers to reach their clients through legitimate management connections. One MSP compromise yielded access to dozens or hundreds of downstream organisations over trusted administrative channels.

    Managed Service ProvidersTechnologyManufacturingAerospace

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.