APT10 is a long-running China-nexus cyber-espionage threat actor publicly linked by the United States government to China’s Ministry of State Security, specifically the Tianjin State Security Bureau, with activity dating back to at least the late 2000s. It is widely tracked under aliases including MenuPass, Stone Panda, Red Apollo, Cicada, POTASSIUM, HOGFISH, BRONZE RIVERSIDE, Granite Taurus, Purple Typhoon, FUNKY FLAGPOLE, and CVNX. Reporting also places newer clusters such as Earth Kasha and Cuckoo Spear within a broader APT10 umbrella, while noting that these should not always be treated as identical to legacy APT10 operations. APT10 is best known for strategic espionage, especially theft of intellectual property, technology-related secrets, and government information. A defining characteristic of the group’s tradecraft is compromise of managed service providers, IT service providers, and other trusted intermediaries to obtain downstream access into customer environments at scale, exemplified by Operation Cloud Hopper. Historic targeting has included technology companies, managed service providers, government agencies, defense-related entities, healthcare, finance, maritime, biotechnology, energy, manufacturing, mining, telecommunications, satellite technology, and other advanced-technology sectors. Documented victim geography includes Japan, India, Taiwan, the United Kingdom, Northern Europe, South America, and the United States. The actor has used spear-phishing attachments, malicious Office documents, disguised executables, and other user-execution lures for initial access, alongside exploitation of public-facing applications and abuse of trusted relationships. Its operational tradecraft includes stealthy long-duration persistence, use of PowerShell, Windows command shell, WMI, InstallUtil, scheduled tasks, malicious macros, DLL search-order hijacking, and legitimate administrative tooling. Credential access and post-compromise activity have included valid-account abuse, credential dumping, Active Directory access, remote services, SMB and administrative shares, RDP, SSH, WMI, and scheduled-task-based lateral movement. APT10-associated malware and tooling reported across campaigns include SOGU, HAYMAKER, SNUGRIDE, BUGJUICE, customized QUASARRAT, RedLeaves, PlugX, UPPERCUT also known as ANEL, ChChes, LODEINFO, NOOPDOOR, and NOOPLDR. Newer activity associated with the broader ecosystem has emphasized stealthy persistence in Japanese networks and use of NOOPDOOR and NOOPLDR, while related Earth Kasha operations have used LODEINFO and ANEL and have targeted organizations in Japan and Taiwan. Collection and exfiltration behavior has included gathering local files, network shared-drive data, and Active Directory information, staging data internally, and compressing or encrypting archives before exfiltration. Overall, APT10 is assessed as a mature, persistent, and operationally flexible Chinese espionage actor focused on long-term access and strategic intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.