Also known as: Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE, MenuPass Team, menuPass, Cloud Hopper, happyyongzi, ATK41, G0045, Granite Taurus, TA429, Purple Typhoon, Hogfish
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018) menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.(Citation: Palo Alto menuPass Feb 2017)(Citation: Crowdstrike CrowdCast Oct 2013)(Citation: FireEye Poison Ivy)(Citation: PWC Cloud Hopper April 2017)(Citation: FireEye APT10 April 2017)(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018)
menuPass; Dust Storm; Cloud Hopper; ChessMaster; Data exfil over common TCP services (RDP, HTTPS)
Targeted Sectors
Executive Summary
The menuPass threat actor, also known as APT10, Cloud Hopper, and Stone Panda, is a sophisticated Chinese-speaking group primarily involved in global espionage targeting critical sectors such as government, defense, healthcare, and aerospace. Known since at least 2006, the group has demonstrated long-term operational persistence and adaptability, leveraging a wide array of tactics to achieve its objectives.
Goals & Targeting
menuPass's primary motivation appears to be espionage, likely aligned with Chinese state interests. The group's targeting profile reflects a strategic focus on sectors that hold sensitive or valuable information, such as defense and aerospace, which are critical to national security. menuPass has demonstrated an ability to adapt its tactics over time, including shifting focus to MSPs in 2016-2017 to broaden its access footprint. The group's victims include government agencies, healthcare providers, energy firms, and biotech companies worldwide, with a notable emphasis on Japanese organizations.
Enhanced Description
menuPass is a highly active cyber threat actor that has been operating since at least 2006. The group has been linked to the Chinese Ministry of State Security (MSS) and the Huaying Haitai Science and Technology Development Company. menuPass has targeted numerous sectors globally, including healthcare, defense, aerospace, government, finance, maritime, biotechnology, energy, and education. Notably, the group has shown a particular focus on Japanese organizations. The actor's tactics have evolved over time, but key activities include espionage campaigns targetingManaged IT service providers (MSPs), manufacturing companies, mining firms, and academic institutions. menuPass is known to employ various techniques including data exfiltration via common TCP services like RDP and HTTPS, the use of custom malware such asPoisonIvyand PlugX, and the exploitation of legitimate tools like Cobalt Strike for malicious purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
menuPass has been involved in multiple campaigns, including 'Cloud Hopper,' 'Dust Storm,' and 'ChessMaster.' The group's operational tempo suggests long-term engagements with victims, often leveraging MSPs to gain broader access. Notable operations include targeting Japanese organizations extensively, as well as academic institutions and manufacturing companies. menuPass is known for its persistence and ability to remain undetected for extended periods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in menuPass's existence and activity based on multiple credible sources, including DOJ indictments and FireEye reports. However, gaps exist in the precise details of current operational toolsets and exact targeting patterns beyond state-level intelligence. Limited visibility into recent campaigns complicates a complete understanding of their evolving Tactics, Techniques, and Procedures (TTPs).
No observed data linked yet.
No IOCs linked yet.
46
Techniques
21
Tools
4
Campaigns
0
IOCs
0
Observed Data
10
Tactics