APT10, also known as menuPass, Stone Panda, Red Apollo, Cicada, POTASSIUM, Purple Typhoon, and Bronze Riverside, is a China-based, Chinese state-backed cyberespionage group. It targets government organizations, cloud-computing managed service providers (MSPs), and customer networks worldwide. Its targeting is particularly prominent in Japan and the United States. The group compromises service-provider environments and abuses valid accounts shared with customers to move between provider and client networks. It has also targeted SAP applications. APT10 uses spearphishing emails containing malicious Microsoft Office documents and executables disguised as documents. Malicious macros execute payloads and invoke legitimate utilities such as certutil to decode concealed content. The group has exploited Pulse Secure VPN vulnerabilities to hijack sessions and used tools exploiting Zerologon (CVE-2020-1472). Its malware includes PlugX, UPPERCUT, and QuasarRAT, alongside modified publicly available tools such as Impacket, Mimikatz, and pwdump. Post-compromise activity includes command-line and reverse-shell access, scripted network enumeration, Active Directory credential dumping with Ntdsutil, and lateral movement through RDP, shared valid accounts, and remote scheduled-task execution. APT10 uses Base64 and single-byte XOR encoding to conceal malware strings and masquerades malicious files as benign documents or text files. It compresses collected data with TAR and RAR before exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
42 malware families attributed to this actor across reporting.
37 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. Earth Lusca, FIN7, menuPass, MuddyWater, and Wizard Spider are also associated with its exploitation or attempted exploitation.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The title of the lure was “2016年台灣總統選舉觀戰團 行程20160105.xls” which translates to “2016 Taiwan president election watching group schedule”. Once the spreadsheet is opened, CVE-2012-0158 is exploited and a file called 6EC5.tmp is dropped in the %TEMP% folder.
Vulnerabilities Exploited : Eternalromance Exploit (CVE-2017-0143). Later in early 2018, the APT10 was seen again carrying out a cyber attack against the systems used in the Pyeongchang, South Korea, WinterOlympics 2018 (using EternalRomance SMB exploit).
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
7 more CVEs tied to this actor tracked in Mallory.
565 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese state-linked actor cited for campaigns compromising healthcare and biotechnology organizations.
Listed as an actor associated with the detection's technique annotation; no specific menuPass campaign or activity is described.
Annotation-only mention; no actor-specific operation or behavior is described.
Listed as an annotation to a renamed-Python-binary detection; no actor-specific campaign or behavior is described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.