Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors menuPass

Also known as: Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE, MenuPass Team, menuPass, Cloud Hopper, happyyongzi, ATK41, G0045, Granite Taurus, TA429, Purple Typhoon, Hogfish

Description

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018) menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.(Citation: Palo Alto menuPass Feb 2017)(Citation: Crowdstrike CrowdCast Oct 2013)(Citation: FireEye Poison Ivy)(Citation: PWC Cloud Hopper April 2017)(Citation: FireEye APT10 April 2017)(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018)

TTP Summary

menuPass; Dust Storm; Cloud Hopper; ChessMaster; Data exfil over common TCP services (RDP, HTTPS)

Goals & Targeting

Targeted Sectors

Government
Defense
Healthcare
Aerospace & defense

AI Analysis

· 1 week ago

Executive Summary

The menuPass threat actor, also known as APT10, Cloud Hopper, and Stone Panda, is a sophisticated Chinese-speaking group primarily involved in global espionage targeting critical sectors such as government, defense, healthcare, and aerospace. Known since at least 2006, the group has demonstrated long-term operational persistence and adaptability, leveraging a wide array of tactics to achieve its objectives.

Goals & Targeting

menuPass's primary motivation appears to be espionage, likely aligned with Chinese state interests. The group's targeting profile reflects a strategic focus on sectors that hold sensitive or valuable information, such as defense and aerospace, which are critical to national security. menuPass has demonstrated an ability to adapt its tactics over time, including shifting focus to MSPs in 2016-2017 to broaden its access footprint. The group's victims include government agencies, healthcare providers, energy firms, and biotech companies worldwide, with a notable emphasis on Japanese organizations.

Enhanced Description

menuPass is a highly active cyber threat actor that has been operating since at least 2006. The group has been linked to the Chinese Ministry of State Security (MSS) and the Huaying Haitai Science and Technology Development Company. menuPass has targeted numerous sectors globally, including healthcare, defense, aerospace, government, finance, maritime, biotechnology, energy, and education. Notably, the group has shown a particular focus on Japanese organizations. The actor's tactics have evolved over time, but key activities include espionage campaigns targetingManaged IT service providers (MSPs), manufacturing companies, mining firms, and academic institutions. menuPass is known to employ various techniques including data exfiltration via common TCP services like RDP and HTTPS, the use of custom malware such asPoisonIvyand PlugX, and the exploitation of legitimate tools like Cobalt Strike for malicious purposes.

Key Capabilities

  • Sophisticated espionage tactics
  • Persistent cyberattacks across multiple sectors
  • Use of custom malware (e.g., PoisonIvy, PlugX)
  • Leverage of legitimate tools like Cobalt Strike
  • Targeting managed IT service providers
  • Data exfiltration via common network protocols

MITRE ATT&CK Tactics

Espionage
Collection
Exfiltration
Lateral Movement
Defense Evasion
Deception

ATT&CK Techniques

T1053.005: Scheduled Task
T1560.001: Archive via Utility
T1047: Windows Management Instrumentation
T1056.001: Keylogging
T1218.004: InstallUtil
T1021.004: SSH
T1566.001: Spearphishing Attachment
T1574.001: DLL
T1199: Trusted Relationship
T1588.002: Tool

Software / Tooling

PoisonIvy
PlugX
Cobalt Strike
RedLeaves
Ecipekac
EvilGrab
SNUGRIDE
FYAnti
HUI Loader
P8RAT
SodaMaster

Campaigns & Victims

menuPass has been involved in multiple campaigns, including 'Cloud Hopper,' 'Dust Storm,' and 'ChessMaster.' The group's operational tempo suggests long-term engagements with victims, often leveraging MSPs to gain broader access. Notable operations include targeting Japanese organizations extensively, as well as academic institutions and manufacturing companies. menuPass is known for its persistence and ability to remain undetected for extended periods.

IOC Patterns

  • Spear-phishing campaigns using macro-laced Office documents
  • Exfiltration data via common protocols like RDP or HTTPS
  • Use of fast-flux domains for command and control
  • Deploying custom malware such as PoisonIvy and PlugX
  • Leveraging Cobalt Strike for initial access or lateral movement
  • Scheduled task creation for persistence

Recommended Actions

  • Implement strict monitoring of RDP and HTTPS traffic for signs of unauthorized data exfiltration.
  • Conduct regular phishing simulations to improve employee awareness of spear-phishing attacks.
  • Apply MFA wherever possible, especially for critical systems and network access points.
  • Monitor for unusual activity in scheduled tasks and system logs related to known menuPass TTPs.
  • Segregate network segments for high-value assets to mitigate lateral movement risks.

Suggested Tags

APT
espionage
china-linked
government-targeting
defense-sector
healthcare-targeting

Confidence Assessment

High confidence in menuPass's existence and activity based on multiple credible sources, including DOJ indictments and FireEye reports. However, gaps exist in the precise details of current operational toolsets and exact targeting patterns beyond state-level intelligence. Limited visibility into recent campaigns complicates a complete understanding of their evolving Tactics, Techniques, and Procedures (TTPs).

ATT&CK Techniques

Collection
8 techniques
Discovery
6 techniques
Execution
6 techniques
Initial Access
3 techniques
Stealth
11 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Accenture Hogfish April 2018 — Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.
  2. SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022 — Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER. Retrieved December 7, 2023.
  3. Crowdstrike CrowdCast Oct 2013 — Crowdstrike. (2013, October 16). CrowdCasts Monthly: You Have an Adversary Problem. Retrieved November 17, 2024.
  4. FireEye APT10 April 2017 — FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.
  5. FireEye Poison Ivy — FireEye. (2014). POISON IVY: Assessing Damage and Extracting Intelligence. Retrieved September 19, 2024.
  6. FireEye APT10 Sept 2018 — Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.
  7. Palo Alto menuPass Feb 2017 — Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017.
  8. PWC Cloud Hopper April 2017 — PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.
  9. Symantec Cicada November 2020 — Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.
  10. DOJ APT10 Dec 2018 — United States District Court Southern District of New York (USDC SDNY) . (2018, December 17). United States of America v. Zhu Hua and Zhang Shilong. Retrieved April 17, 2019.
  11. District Court of NY APT10 Indictment December 2018 — US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.

Intel Summary

46

Techniques

21

Tools

4

Campaigns

0

IOCs

0

Observed Data

10

Tactics

Tags

APT
Healthcare Targeting
Data Exfiltration
Government Targeting
espionage
china-linked
government-targeting
defense-sector
healthcare-targeting

Details

MITRE ID
G0045
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--222fbd21-fc4f-4b7e-9f85-0e6e3a76c33f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.