Operation Cloud Hopper was identified as a large-scale cyber espionage campaign that compromised managed service providers (MSPs) to gain access to both the providers and their downstream customer environments. Incident responders from PwC and BAE Systems said the activity was discovered in late 2016 and involved theft of intellectual property and other sensitive business information from organizations connected through trusted IT outsourcing relationships.
The campaign was attributed with high confidence to APT10, based on overlaps with earlier operations including infrastructure and command-and-control patterns. Reporting linked the group to China, citing indicators such as UTC+8 working patterns, domain registration timing, binary compile times, and victim targeting aligned with Chinese strategic interests, while noting that the operation marked a significant increase in the group’s scale and capability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The campaign targeted managed IT service providers to steal the providers' sensitive data and gain access to the networks and data of their customers worldwide, potentially reaching thousands of networks through a small number of MSP compromises.
In late 2016, PwC and BAE Systems began assisting victims of a newly identified global cyber espionage campaign later named Operation Cloud Hopper.
PwC and BAE's Cloud Hopper assessment said APT10 had significantly increased its scale and capability since early 2016, marking an escalation in the group's operational reach.
A federal grand jury in the Southern District of New York indicted Zhu Hua and Zhang Shilong on charges including conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft. The indictment identified them as APT10 members linked to China's Ministry of State Security and alleged a global intrusion campaign affecting MSPs, technology firms, government agencies, and more than 100,000 U.S. Navy personnel records.
The assessment concluded APT10 was highly likely to be China-based, based on indicators including compile times, domain registration times, UTC+8 working patterns, and targeting aligned with China's strategic interests.
PwC and BAE Systems assessed that Operation Cloud Hopper was almost certainly conducted by APT10, citing overlaps between Cloud Hopper infrastructure and command-and-control domains tied to the group's earlier operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
darknetdiaries.com
Open sourcefbi.gov
Open sourceintrusiontruth.wordpress.com
Open sourcepwc.co.uk
Open sourcepwc.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.