APT10 is a Chinese nation-state threat actor targeting government and private sectors across multiple nations.
Analyst brief
APT10 (also known as STONE PANDA) is a Chinese nation-state threat actor active since at least 2006. The group primarily targets government and private sectors across Japan, the United States, South Korea, and other nations. It leverages TTPs such as Spearphishing Attachment and Trusted Relationship for initial access, deploying malware like Cobalt Strike and PlugX alongside tools like Mimikatz and PsExec. Defenders should prioritize monitoring for lateral movement via RDP, NTDS credential dumping, and C2 communications using External Proxy.
APT10
STONE PANDAMenupass Teamhappyyongzi
nation-state
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)