Cyber threat actor
APT10
MSS Tianjin State Security Bureau · active since 2009
Operation Cloud Hopper, global managed service provider (MSP) compromise enabling downstream access to thousands of client organizations.
Aliases
Stone PandamenuPassPOTASSIUM
Primary targets
Managed Service Providers Engineering Aerospace Healthcare Government
MITRE ATT&CK techniques
3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1199 Trusted Relationship (MSP) | Operation Cloud Hopper, compromised managed service providers to pivot into thousands of downstream client networks. | Global MSPs, engineering, aerospace | PwC Cloud Hopper |
| Persistence | T1543.003 Windows Service (PlugX/RedLeaves) | ChChes, RedLeaves and PlugX installed as Windows services for persistence across customer tenants. | - | PwC Cloud Hopper |
| Lateral Movement | T1021 Remote Services (stolen creds) | Used MSP admin credentials to authenticate into customer environments through trusted RMM channels. | - | PwC Cloud Hopper |