TLP:CLEAR
⚠ NATION-STATE · MSS TIANJIN BUREAU · CHINA
// Threat Actor Profile — State-Sponsored Espionage / MSP Supply-Chain Specialist

MENUPASS

PROFILE COMPILED: 2026-09-04  |  SOURCES: MITRE ATT&CK, US DOJ/FBI, NCSC UK, PwC/BAE Systems, CrowdStrike, Mandiant, Trend Micro, Secureworks, Kaspersky, EU Council, Palo Alto Unit 42
Status: ACTIVE
Threat Level: CRITICAL
Primary Motive: Espionage / IP & Business Intelligence Theft
Active Since: 2006 (at least)
MITRE ATT&CK: G0045
45+
MSPs Compromised (Operation Cloud Hopper)
30+
Countries With Documented Targeting
20+
Years of Continuous Activity (2006–2026)
2
DOJ-Indicted Individuals (SDNY, Dec 2018)
00
Overview

menuPass — tracked across the industry as APT10, Stone Panda, Red Apollo, and a half-dozen other vendor names — is one of the longest-running, most thoroughly attributed Chinese state cyber-espionage operations on public record. Active since at least 2006 (MITRE ATT&CK, Group G0045), the group operates on behalf of the Ministry of State Security's Tianjin State Security Bureau, with individual members documented as having worked through the front company Huaying Haitai Science and Technology Development Co. Ltd. Unlike destructive or financially-motivated actors, menuPass's objective has remained constant across two decades: systematic theft of intellectual property, business intelligence, and government/defense information in direct support of Chinese national strategic and industrial priorities.

The group's defining contribution to the threat landscape is Operation Cloud Hopper — publicly exposed in April 2017 by a joint PwC UK and BAE Systems investigation, which found menuPass had compromised more than 45 managed IT service providers across at least a dozen countries, using each MSP's own privileged remote-administration access as a pivot into the networks of its downstream clients (PwC/BAE Systems, Apr 2017). This was not an isolated campaign but the formalization of an access model: compromise one trusted intermediary, inherit its client base. The scale of Cloud Hopper — later reporting suggested dozens of additional MSPs beyond the original disclosure — was significant enough that it drove a rare seven-nation joint attribution statement in December 2018 (US, UK, Australia, Canada, New Zealand, Japan, and the Netherlands), coordinated with a US Department of Justice indictment of two named individuals, Zhu Hua and Zhang Shilong, for conspiracy to commit computer intrusion, wire fraud, and aggravated identity theft (DOJ/SDNY, Dec 17 2018).

menuPass matters today not as a historical case study but as a live, adaptive threat. Distinct from — but closely related to — a cluster Trend Micro tracks separately as Earth Kasha (part of what the vendor terms the broader "APT10 Umbrella"), Japan-focused operations using LODEINFO and NOOPDOOR malware have continued into 2025, with a documented pivot away from spearphishing and toward direct exploitation of internet-facing SSL-VPN and file-storage appliances as the primary access vector (Trend Micro, 2024–2025). This shift — from a labor-intensive social-engineering model to opportunistic edge-device exploitation — mirrors a broader trend across Chinese state-linked operators and means menuPass-umbrella activity is now discoverable through vulnerability-scanning telemetry as well as phishing-detection pipelines.

Where menuPass sits in the current threat landscape is therefore dual: it is simultaneously a textbook example of supply-chain-enabled espionage (the Cloud Hopper model remains a reference case for MSP risk assessments industry-wide) and an actively evolving operator whose current tooling and initial-access preferences continue to shift. Organizations providing managed IT services to government, defense, or intellectual-property-rich clients — and any organization operating internet-facing SSL-VPN or file-transfer infrastructure with a Japan, Taiwan, or broader Asia-Pacific footprint — should treat this profile as current operational risk, not archived history.

01
Identity & Attribution
Primary NamemenuPass
Sponsor / ParentChinese Ministry of State Security — Tianjin State Security Bureau
Actor TypeNation-State APT — Contractor Model
Primary MotivationEspionage — IP theft, business intelligence, defense/government intelligence
Active SinceAt least 2006 (MITRE); some vendor profiles date sustained operations from 2009
Last Observed2025 — continued Earth Kasha/APT10-Umbrella activity against Japan and Taiwan (Trend Micro)
MITRE G-IDG0045
Legal StatusUS DOJ indictment (SDNY, Dec 17 2018) — both defendants remain at large; EU cyber-sanctions regime designation (Jul 2020) on front company + 2 individuals
Tracking Aliases
menuPass APT10 Stone Panda Red Apollo Cicada CVNX HOGFISH BRONZE RIVERSIDE POTASSIUM (Microsoft, legacy) Purple Typhoon (Microsoft, current)
Attribution Confidence

[HIGH] for the core menuPass/APT10 identity and its Tianjin-bureau MSS sponsorship. This rests on an unusually strong evidentiary base for a nation-state actor: a criminal indictment naming individuals (a US federal grand jury standard, not just an intelligence assessment), a coordinated seven-nation government attribution statement, EU Council sanctions designations, and consistent independent convergent tracking by at least six major vendors since the mid-2000s. Confidence is [MEDIUM], not HIGH, for whether 2023–2025 LODEINFO/NOOPDOOR activity (tracked by Trend Micro as "Earth Kasha," part of the broader "APT10 Umbrella") represents the same operational unit as the core DOJ-indicted menuPass cluster, versus a related-but-organizationally-distinct group sharing tooling lineage and targeting doctrine — Trend Micro's own reporting explicitly declines to fully conflate the two, and this card follows that caution rather than overclaiming a single unified actor.

02
Campaign & Operational Timeline
2006–2013
Foundational Espionage Operations
Earliest documented activity (MITRE ATT&CK), predominantly direct spearphishing intrusions against defense, aerospace, and government targets, using early custom tooling (Poison Ivy, ChChes — named by JPCERT) and the group's own PlugX RAT, which multiple vendors assess menuPass had a direct hand in developing.
2014–2016
MSP-Supply-Chain Pivot Begins
PwC/BAE Systems assess that systematic MSP targeting — the pattern that would become Operation Cloud Hopper — likely began as early as 2014, with confirmed multi-provider targeting from 2016 onward. Domain registration timing patterns analyzed in the PwC report align with China Standard Time.
Apr 2017
Operation Cloud Hopper Publicly Exposed
PwC UK and BAE Systems jointly publish findings of a year-long investigation: 45+ managed IT service providers compromised across at least a dozen countries, granting downstream access into the networks of Fortune 500 companies, US government agencies, and defense-industrial-base entities that had never been directly breached themselves (PwC/BAE Systems, Apr 2017).
Dec 2018
Seven-Nation Attribution & DOJ Indictment
US DOJ/SDNY indicts Zhu Hua and Zhang Shilong (Huaying Haitai Science and Technology Development Co.) on charges spanning conspiracy to commit computer intrusion, wire fraud, and aggravated identity theft, covering intrusions into 45+ commercial/defense companies and multiple US government agencies since at least 2006 (DOJ, Dec 17 2018). Simultaneously, the US, UK, Australia, Canada, New Zealand, Japan, and the Netherlands issue a coordinated public attribution statement — a rare multilateral response reserved for the most significant state-linked campaigns.
2019–2023
A41APT — Long-Dwell Japan Campaign
Kaspersky documents the A41APT campaign (tracked in related industry reporting under Secureworks' BRONZE RIVERSIDE designation), a sustained multi-year operation against Japanese organizations using the sophisticated multi-layered Ecipekac loader to deliver the SodaMaster RAT and other payloads via HUI Loader — a delivery chain in continuous use since at least 2015 (Kaspersky Securelist).
Jul 2020
EU Cyber Sanctions Regime Designation
The European Union designates Huaying Haitai Science and Technology Development Co. and individuals Zhang Shilong and Gao Qiang under its (then-new) cyber sanctions framework, formally citing their role in providing material and technical support to Operation Cloud Hopper — among the first designations made under the EU's cyber sanctions regime.
2023–2025
Pivot to Edge-Device Exploitation (Earth Kasha / APT10 Umbrella)
Trend Micro documents a second, tactically distinct LODEINFO campaign phase beginning 2023: initial access shifts from spearphishing to direct exploitation of internet-facing SSL-VPN and file-storage appliances (CVE-2023-28461 — Array Networks AG; CVE-2023-45727 — Proself; CVE-2023-27997 — FortiOS/FortiProxy), paired with the NOOPDOOR secondary backdoor for 2–3+ year persistence. March 2025 reporting confirms continued targeting of Taiwan and Japan using ANEL, SharpHide, and NOOPDOOR against government and high-technology sector targets (Trend Micro, Mar 2025).
03
Attack Lifecycle Two coexisting access models: MSP-supply-chain and direct edge exploitation

Initial access has evolved across two eras without either fully retiring. The historically dominant model — and the one responsible for Operation Cloud Hopper's scale — is trusted-relationship abuse: menuPass compromises a managed IT service provider (via spearphishing with malicious macro-laden documents, historically the group's primary lure vector) and then rides the MSP's own legitimate remote-administration tooling and credentials directly into client networks, a technique that requires no additional exploitation once the MSP itself is breached (PwC/BAE Systems, 2017). The newer model, documented from 2023 onward in the Earth Kasha/APT10-Umbrella cluster, targets internet-facing SSL-VPN gateways and file-storage/transfer appliances directly via disclosed CVEs, bypassing the need for a human-targeted phishing lure entirely (Trend Micro, 2024).

Toolchain and delivery center on a family of custom loaders — HUI Loader (in continuous use since ~2015), the more sophisticated multi-layered Ecipekac loader, ChChes, and FYAnti — that deploy via DLL side-loading against legitimate signed executables, a technique chosen specifically to blend malicious module loading into what endpoint tooling sees as normal process activity. These loaders deliver a rotating set of backdoors: PlugX and RedLeaves historically, UPPERCUT/ANEL and SodaMaster in the A41APT era, and LODEINFO paired with the NOOPDOOR secondary implant in current Earth Kasha-cluster operations. LODEINFO functions as the primary, feature-rich backdoor (shellcode execution, keylogging, screen capture, file exfiltration); NOOPDOOR — which shares code lineage with ANEL — is deployed as a lower-profile secondary implant specifically to preserve access if the primary backdoor is discovered, and has been observed maintaining persistence for two to three years in a single victim environment (Trend Micro, 2024).

Post-compromise tradecraft leans heavily on dual-use and living-off-the-land tooling once inside a network: Mimikatz and pwdump for credential access, AdFind for Active Directory reconnaissance, and Impacket/PsExec alongside native RDP and SSH for lateral movement — all chosen because they are difficult to distinguish from legitimate administrator activity, especially inside an MSP's own management infrastructure where such tools are expected to be present. Cobalt Strike has been observed delivered via the HUI Loader chain as a COTS force-multiplier for later-stage operations. Command and control infrastructure mixes actor-registered domains with a smaller proportion of Dynamic DNS domains (Palo Alto Unit 42), and exfiltration is conducted over the same backdoor C2 channel rather than a separate dedicated exfil path — consistent with an operational preference for minimizing distinct, separately-detectable infrastructure footprints across a long-dwell-time campaign.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework — no ICS/ATLAS activity documented for this actor
Reconnaissance
T1591
Gather Victim Org Information
[HIGH] MSP client-relationship mapping conducted prior to targeting downstream victims via a compromised provider (PwC/BAE Systems, 2017).
Initial Access
T1566.001
Phishing: Spearphishing Attachment
[HIGH] Malicious macro-laden documents historically the primary lure vector against direct targets and MSP staff alike.
Initial Access
T1199
Trusted Relationship
[HIGH] The Operation Cloud Hopper signature — abusing compromised MSPs' privileged remote-administration relationships to reach client networks.
Initial Access
T1190
Exploit Public-Facing Application
[MEDIUM] Documented for the Earth Kasha/APT10-Umbrella cluster specifically (CVE-2023-28461, CVE-2023-45727, CVE-2023-27997) — not confirmed for the core DOJ-indicted menuPass identity (Trend Micro, 2024).
Execution
T1059.005
Command and Scripting Interpreter: VBA
[HIGH] Macro-based execution chains documented across the group's spearphishing operations since at least 2013.
Persistence / Defense Evasion
T1574.002
Hijack Execution Flow: DLL Side-Loading
[HIGH] Signature delivery mechanism for HUI Loader, Ecipekac, and ChChes against legitimate signed binaries.
Defense Evasion
T1055
Process Injection
[MEDIUM] Documented in Ecipekac's multi-layered loading chain during the A41APT campaign (Kaspersky Securelist).
Credential Access
T1003.001
OS Credential Dumping: LSASS Memory
[HIGH] Mimikatz and pwdump documented in post-compromise tradecraft across multiple campaign eras.
Discovery
T1087 / T1018
Account & Remote System Discovery
[HIGH] AdFind used for Active Directory enumeration inside compromised MSP and client environments.
Lateral Movement
T1021.001 / T1021.004
Remote Services: RDP / SSH
[HIGH] Native remote-access protocols preferred specifically because they are expected traffic inside MSP management infrastructure.
Lateral Movement
T1570
Lateral Tool Transfer
[MEDIUM] PsExec and Impacket-based toolsets documented for cross-host tool staging.
Command & Control
T1071.001
Application Layer Protocol: Web Protocols
[HIGH] PlugX, LODEINFO, and related backdoors communicate over HTTP/HTTPS-based custom C2 protocols.
Command & Control
T1568
Dynamic Resolution
[MEDIUM] Mixed use of Dynamic DNS alongside actor-registered domains for C2 infrastructure (Palo Alto Unit 42).
Exfiltration
T1041
Exfiltration Over C2 Channel
[MEDIUM] Data exfiltrated over the same backdoor channel used for command and control rather than a separate path.
05
Targeting Profile
Sector Targeting
Managed IT Service Providers
PRIMARY
Government & Public Sector
PRIMARY
Defense & Aerospace
HIGH
Healthcare & Biotechnology
HIGH
High Technology / Academia
HIGH
Energy
MED
Finance / Manufacturing / Mining
MED
Maritime
LOW
GeographiesHistoric footprint across 30+ countries; sustained emphasis on Japan since 2019, with continued Taiwan, US, UK, and broader Europe/Southeast Asia targeting
Victim ProfileFortune 500 and government/defense entities reached indirectly via compromised MSPs; direct government and high-tech targeting in current Japan/Taiwan operations
Preferred EntryHistorically: spearphishing + MSP trusted-relationship abuse. Since 2023: direct exploitation of internet-facing SSL-VPN and file-storage appliances
Target DoctrineIntellectual property and business intelligence theft aligned to Chinese industrial and strategic priorities — not financially or destructively motivated
06
Tools, Malware & Infrastructure
PLUGX RAT (Custom) · T1071.001
Modular RAT with plugin-based architecture (compressed/encrypted C2 comms, network enumeration, file operations, remote shell) that multiple vendors assess menuPass had a direct hand in developing. In continuous use since the group's earliest documented operations through recent campaigns; also widely proliferated to other China-linked actors, making PlugX presence alone a weak standalone attribution signal without corroborating TTPs.
HUI LOADER Loader · T1574.002
DLL side-loading delivery mechanism in continuous use since approximately 2015, used to deploy Cobalt Strike, QuasarRAT, PlugX, and SodaMaster against legitimate signed-binary hosts to evade signature-based detection (Secureworks CTU).
ECIPEKAC Loader (Custom, Multi-Layered) · T1055
Sophisticated multi-layered loader discovered in the A41APT campaign against Japanese organizations; each layer decrypts and loads the next stage in memory, a specific design choice to defeat static file-based analysis (Kaspersky Securelist, 2021).
LODEINFO Backdoor · T1071.001 · Earth Kasha / APT10 Umbrella [MEDIUM confidence core-menuPass link]
Primary backdoor in campaigns active 2019–2025 against Japan (and, since 2023, Taiwan). Supports shellcode execution, keylogging, screenshot capture, process termination, and file exfiltration to actor-controlled infrastructure. Delivered via the LODEINFOLDR loader, which abuses CVE-2013-3900 (WinVerifyTrust signature validation) to embed and later decrypt (RC4/XOR) a payload hidden inside a legitimate binary's digital signature block (Trend Micro, 2024).
NOOPDOOR / NOOPLDR Secondary Backdoor · Earth Kasha / APT10 Umbrella [MEDIUM confidence core-menuPass link]
Secondary implant sharing code lineage with the group's ANEL/UPPERCUT backdoor family, deployed specifically to preserve access if LODEINFO (the primary backdoor) is discovered and removed. Documented maintaining persistence in single victim environments for two to three years (Trend Micro, 2024).
UPPERCUT / ANEL Backdoor (Custom)
Longstanding custom backdoor family, tracked by Secureworks specifically under its BRONZE RIVERSIDE designation for continued Japan-focused updates to the ANEL malware line.
COBALT STRIKE C2 Framework (COTS)
Commercial red-team framework delivered via the HUI Loader chain as a force-multiplier for later-stage post-compromise operations.
MIMIKATZ / PWDUMP Credential Access (COTS/OSS)
Standard credential-dumping tooling used against LSASS memory following initial access, prior to lateral movement.
ADFIND / IMPACKET / PSEXEC LOLBin / Dual-Use
Active Directory reconnaissance (AdFind) and lateral movement/remote execution (Impacket, PsExec) chosen specifically because their presence is unremarkable inside MSP administrative environments, where such tools are legitimately expected.
CHCHES / REDLEAVES / SNUGRIDE / BUGJUICE / HAYMAKER / SODAMASTER / P8RAT / FYANTI Backdoor Family (Custom, Various Campaigns)
Rotating set of custom backdoors documented across different campaign windows since 2015; ChChes was named by JPCERT/CC in 2017 reporting on the group's Japan-focused activity. Functional overlap across the family (remote shell, file transfer, basic system reconnaissance) with differing packers/obfuscation per campaign generation.
EXPLOITED CVES (EARTH KASHA / APT10 UMBRELLA) Initial Access · T1190
CVE-2023-28461 (Array Networks AG SSL-VPN), CVE-2023-45727 (Proself file-transfer appliance), and CVE-2023-27997 (FortiOS/FortiProxy) exploited in the wild as initial access since 2023. Vulnerability cross-link: none of these CVEs currently have a companion card in this project's output/vulns/ library (current roster: Heartbleed, Spectre/Meltdown, PaperCut, PrintNightmare, Rockwell Logix Auth Bypass, WatchGuard Firebox Auth Bypass, SonicWall SonicOS Access Control, Chrome WebGL OOB Write — none match). Stated as an open gap rather than a fabricated cross-reference.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
CVECVE-2023-28461 — Array Networks AG SSL-VPN, exploited for initial accessTrend Micro2023
CVECVE-2023-45727 — Proself file-transfer appliance, exploited for initial accessTrend Micro2023
CVECVE-2023-27997 — FortiOS/FortiProxy, exploited for initial accessTrend Micro2023
CVECVE-2013-3900 — WinVerifyTrust signature-validation abuse, used by LODEINFOLDR to hide encrypted payload inside a legitimate digital signatureTrend Micro2024
MALWARELODEINFO, NOOPDOOR/NOOPLDR, PlugX, HUI Loader, Ecipekac, ChChes, RedLeaves, SNUGRIDE, BUGJUICE, HAYMAKER, UPPERCUT/ANEL, SodaMaster, P8RAT, FYAnti (family names — specific current sample hashes not independently verified in this research pass)MITRE ATT&CK / Multiple Vendors2017–2025
INFRAC2 infrastructure documented as a mix of actor-registered domains and a smaller proportion of Dynamic DNS domains — specific current domain values not independently reproduced in this cardPalo Alto Unit 422017
NOTENo specific current file hashes, C2 domains, or IP addresses were independently verified firsthand during this research pass. Vendor playbooks (notably Palo Alto Unit 42's "menuPass Playbook and IOCs") publish detailed hash/domain appendices — consult those directly for operational blocklisting rather than treating the malware-family names above as sufficient detection signal on their own.Analyst Note2026-09-04
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH (core identity) / MEDIUM (2023–2025 Earth Kasha linkage)
TrajectoryActive and adapting — pivoting toward edge-device exploitation, not declining
Most Dangerous CapabilityMSP trusted-relationship abuse — a single compromise multiplies into many client networks
Primary Intel GapOrganizational relationship between core menuPass and the Earth Kasha/APT10-Umbrella cluster
Ecosystem / Affiliated Groups
Earth Kasha (Trend Micro tracking — related, not confirmed identical) APT10 Umbrella (Trend Micro's broader cluster designation)

menuPass earns a CRITICAL threat-level assessment on the strength of demonstrated impact rather than novelty: Operation Cloud Hopper remains one of the highest-leverage espionage campaigns ever publicly documented, precisely because compromising a single MSP granted access to dozens of downstream victims who had implemented no failure of their own. That access model — not any single piece of malware — is the group's most dangerous capability, and it generalizes to any organization that outsources IT administration to a third party with standing privileged access.

The most significant open question this assessment cannot resolve with available public sourcing is the precise organizational relationship between the core, DOJ-indicted menuPass identity and the newer Earth Kasha/APT10-Umbrella cluster responsible for 2023–2025 LODEINFO/NOOPDOOR activity against Japan and Taiwan. Trend Micro — the vendor with the deepest visibility into this specific cluster — explicitly states it does not have sufficient evidence to fully confirm the two are the same operational unit, describing them instead as related but analytically distinct within a broader "APT10 Umbrella." This card follows that same caution: claims specific to core menuPass (Cloud Hopper, the DOJ indictment, PlugX/HUI Loader/Ecipekac tradecraft) are held at [HIGH] confidence; claims specific to the Earth Kasha cluster's CVE-driven initial access and LODEINFO/NOOPDOOR tooling are held at [MEDIUM] confidence for their linkage to the core identity, even though the tooling lineage (shared code with ANEL/UPPERCUT) and consistent Japan-centric targeting doctrine make some relationship highly plausible. What would raise this to [HIGH]: a government attribution statement or DOJ filing explicitly naming Earth Kasha activity as menuPass/APT10, analogous to the 2018 indictment's treatment of Cloud Hopper.

Forward risk trajectory is upward, not stable. The 2023 pivot from spearphishing toward direct SSL-VPN/file-storage appliance exploitation is a rational adaptation — it removes dependency on a human clicking a malicious attachment and instead exploits scanning-detectable but often unpatched edge infrastructure, a pattern now common across multiple Chinese state-linked operators. Any organization running Array Networks AG, Proself, or FortiOS/FortiProxy infrastructure with unpatched instances of the associated 2023 CVEs should treat menuPass/Earth-Kasha-umbrella activity as a live, not historical, risk — particularly given documented 2–3 year dwell times once NOOPDOOR achieves persistence.

09
Defensive Recommendations
01
Segment and limit MSP remote-administration access to only the specific systems and privilege levels required, with time-bounded/just-in-time access rather than standing credentials.
Counters: T1199 Trusted Relationship
02
Patch and prioritize internet-facing SSL-VPN and file-transfer appliances — specifically Array Networks AG, Proself, and FortiOS/FortiProxy instances vulnerable to CVE-2023-28461, CVE-2023-45727, and CVE-2023-27997.
Counters: T1190 Exploit Public-Facing Application
03
Deploy macro-execution restrictions (block VBA macros from internet-sourced Office documents by default) across any organization historically or currently targeted by spearphishing-based initial access.
Counters: T1566.001, T1059.005
04
Monitor for unsigned/unexpected DLL loads by known-legitimate signed executables — the primary detection opportunity against HUI Loader, Ecipekac, and ChChes delivery.
Counters: T1574.002 DLL Side-Loading
05
Alert on AdFind, Impacket, and PsExec execution outside documented administrative change windows, especially within MSP-managed infrastructure where such tools are otherwise routine.
Counters: T1087, T1018, T1570
06
Enforce LSASS memory protections (Credential Guard, LSA Protection) to reduce Mimikatz/pwdump effectiveness following initial access.
Counters: T1003.001
07
Hunt for long-dwell secondary implants specifically — NOOPDOOR's documented 2–3 year persistence means a single detected backdoor should not be treated as full remediation; assume a secondary implant until proven otherwise.
Counters: T1071.001 (NOOPDOOR persistence pattern)
08
Baseline and alert on Dynamic DNS resolution requests from endpoints that have no legitimate business reason to resolve DDNS domains.
Counters: T1568 Dynamic Resolution
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
C2 domain strategy mixes actor-registered domains with a smaller share of Dynamic DNS domains (Palo Alto Unit 42), a deliberate hedge that provides some registration-pattern deniability (DDNS domains require less identity disclosure) while retaining actor-registered infrastructure for higher-stability long-term operations. Specific current rotation cadence not documented in sources reviewed.
Living-off-the-Land Ratio
[HIGH]
Heavy reliance on dual-use tooling (AdFind, Impacket, PsExec, native RDP/SSH, certutil, esentutl) for the discovery, credential-access, and lateral-movement phases specifically — chosen because these tools are routinely present and expected inside MSP administrative environments, making their use far less anomalous than a custom implant performing the same functions. Custom malware (PlugX, LODEINFO family) is reserved for initial-access delivery and long-term backdoor persistence, where a bespoke tool's added capability outweighs its detection risk.
Tooling Hygiene [HIGH]
Digital-signature abuse as a specific, sourced hygiene technique: the LODEINFOLDR loader exploits CVE-2013-3900 (incomplete WinVerifyTrust Authenticode validation) to embed an RC4/XOR-encrypted payload inside a legitimate file's own digital signature block, extracting and decrypting it at runtime — a technique specifically chosen to defeat static signature-based file scanning while the carrier file itself still presents a valid-looking signature to less rigorous validators (Trend Micro, 2024).
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
DLL Side-Loading via HUI Loader / Ecipekac / ChChes T1574.002
EDR BYPASS
Legitimate signed executables are used to side-load a malicious DLL, causing the malicious code to execute in the context of a trusted, signed process — a specific and repeated design choice across three separate loader generations (Secureworks CTU, Kaspersky Securelist).
Specific binary names and loader/DLL pairings used per campaign are not consistently published across the sources reviewed for this card — consult Kaspersky's A41APT/Ecipekac writeup and Secureworks' BRONZE RIVERSIDE reporting directly for current sample-level detail. Not fabricated here.
Digital Signature / WinVerifyTrust Abuse (CVE-2013-3900) T1027 (Obfuscated Files or Information — analogue)
EDR BYPASS SIEM EVASION
The LODEINFOLDR loader embeds an encrypted payload inside a legitimate file's Authenticode signature block, then decrypts it with RC4 or XOR at runtime — defeating file-integrity assumptions that treat a validly-signed file as inherently trustworthy (Trend Micro, 2024).
Decryption method confirmed as RC4/XOR per Trend Micro's published analysis; specific per-sample keys and byte offsets are not publicly documented as of 2026-09-04.
Living-off-the-Land Discovery & Lateral Movement T1087, T1018, T1570
SIEM EVASION
AdFind, Impacket, and PsExec usage blends into expected MSP administrative activity, specifically defeating log-based detection that alerts on "unknown tool" presence rather than anomalous usage patterns of known-legitimate administrative tools.
Specific command-line arguments not consistently publicly documented across sources reviewed as of 2026-09-04 — stated explicitly rather than fabricated.
Dynamic DNS / Mixed C2 Registration T1568
NETWORK
Blending actor-registered domains with Dynamic DNS domains reduces the reliability of registration-pattern-based domain reputation scoring as a standalone detection signal (Palo Alto Unit 42).
Specific DDNS providers and current domain patterns not independently reproduced in this card — consult Unit 42's menuPass playbook and IOC appendix directly.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — ADVERSARY EMULATION PLAN menuPass Adversary Emulation Plan
The Center for Threat-Informed Defense publishes a full menuPass emulation plan split into two scenarios. Scenario 1 emulates the group's MSP-supply-chain access pattern — TTPs specific to targeting MSP subscriber networks via a compromised provider relationship. Scenario 2 emulates menuPass's broader operational tradecraft using a command-and-control framework, assessing an organization's ability to protect, detect, and defend against execution, discovery, privilege escalation, credential access, lateral movement, exfiltration, command and control, and persistence.
Scenario 1 — MSP Subscriber Access Scenario 2 — Execution Discovery Privilege Escalation Credential Access Lateral Movement Exfiltration Command & Control Persistence
Additional Emulation Resources
AttackIQ
Automated emulation build on the CTID plan · Accessed: 2026-09-04
Analyst Note
No dedicated Atomic Red Team test bundle or Sigma rule pack specifically labeled for menuPass/APT10 was confirmed during this research pass — GitHub code search for repo-specific coverage was not performed with authenticated access in this session; do not treat this as a confirmed absence, only as unverified in this pass.
Gap Note · 2026-09-04
13
References URLs are NOT defanged — navigate directly
MITRE ATT&CK
Accessed: 2026-09-04
FBI
Accessed: 2026-09-04
PwC UK / BAE Systems
Apr 2017 · Accessed: 2026-09-04
NCSC UK
Dec 2018 · Accessed: 2026-09-04
CrowdStrike
Accessed: 2026-09-04
The Hacker News
Jul 2024 · Accessed: 2026-09-04
Secureworks CTU
Accessed: 2026-09-04
Palo Alto Unit 42
Accessed: 2026-09-04
MITRE Engenuity / CTID
Accessed: 2026-09-04