menuPass — tracked across the industry as APT10, Stone Panda, Red Apollo, and a half-dozen other vendor names — is one of the longest-running, most thoroughly attributed Chinese state cyber-espionage operations on public record. Active since at least 2006 (MITRE ATT&CK, Group G0045), the group operates on behalf of the Ministry of State Security's Tianjin State Security Bureau, with individual members documented as having worked through the front company Huaying Haitai Science and Technology Development Co. Ltd. Unlike destructive or financially-motivated actors, menuPass's objective has remained constant across two decades: systematic theft of intellectual property, business intelligence, and government/defense information in direct support of Chinese national strategic and industrial priorities.
The group's defining contribution to the threat landscape is Operation Cloud Hopper — publicly exposed in April 2017 by a joint PwC UK and BAE Systems investigation, which found menuPass had compromised more than 45 managed IT service providers across at least a dozen countries, using each MSP's own privileged remote-administration access as a pivot into the networks of its downstream clients (PwC/BAE Systems, Apr 2017). This was not an isolated campaign but the formalization of an access model: compromise one trusted intermediary, inherit its client base. The scale of Cloud Hopper — later reporting suggested dozens of additional MSPs beyond the original disclosure — was significant enough that it drove a rare seven-nation joint attribution statement in December 2018 (US, UK, Australia, Canada, New Zealand, Japan, and the Netherlands), coordinated with a US Department of Justice indictment of two named individuals, Zhu Hua and Zhang Shilong, for conspiracy to commit computer intrusion, wire fraud, and aggravated identity theft (DOJ/SDNY, Dec 17 2018).
menuPass matters today not as a historical case study but as a live, adaptive threat. Distinct from — but closely related to — a cluster Trend Micro tracks separately as Earth Kasha (part of what the vendor terms the broader "APT10 Umbrella"), Japan-focused operations using LODEINFO and NOOPDOOR malware have continued into 2025, with a documented pivot away from spearphishing and toward direct exploitation of internet-facing SSL-VPN and file-storage appliances as the primary access vector (Trend Micro, 2024–2025). This shift — from a labor-intensive social-engineering model to opportunistic edge-device exploitation — mirrors a broader trend across Chinese state-linked operators and means menuPass-umbrella activity is now discoverable through vulnerability-scanning telemetry as well as phishing-detection pipelines.
Where menuPass sits in the current threat landscape is therefore dual: it is simultaneously a textbook example of supply-chain-enabled espionage (the Cloud Hopper model remains a reference case for MSP risk assessments industry-wide) and an actively evolving operator whose current tooling and initial-access preferences continue to shift. Organizations providing managed IT services to government, defense, or intellectual-property-rich clients — and any organization operating internet-facing SSL-VPN or file-transfer infrastructure with a Japan, Taiwan, or broader Asia-Pacific footprint — should treat this profile as current operational risk, not archived history.
[HIGH] for the core menuPass/APT10 identity and its Tianjin-bureau MSS sponsorship. This rests on an unusually strong evidentiary base for a nation-state actor: a criminal indictment naming individuals (a US federal grand jury standard, not just an intelligence assessment), a coordinated seven-nation government attribution statement, EU Council sanctions designations, and consistent independent convergent tracking by at least six major vendors since the mid-2000s. Confidence is [MEDIUM], not HIGH, for whether 2023–2025 LODEINFO/NOOPDOOR activity (tracked by Trend Micro as "Earth Kasha," part of the broader "APT10 Umbrella") represents the same operational unit as the core DOJ-indicted menuPass cluster, versus a related-but-organizationally-distinct group sharing tooling lineage and targeting doctrine — Trend Micro's own reporting explicitly declines to fully conflate the two, and this card follows that caution rather than overclaiming a single unified actor.
Initial access has evolved across two eras without either fully retiring. The historically dominant model — and the one responsible for Operation Cloud Hopper's scale — is trusted-relationship abuse: menuPass compromises a managed IT service provider (via spearphishing with malicious macro-laden documents, historically the group's primary lure vector) and then rides the MSP's own legitimate remote-administration tooling and credentials directly into client networks, a technique that requires no additional exploitation once the MSP itself is breached (PwC/BAE Systems, 2017). The newer model, documented from 2023 onward in the Earth Kasha/APT10-Umbrella cluster, targets internet-facing SSL-VPN gateways and file-storage/transfer appliances directly via disclosed CVEs, bypassing the need for a human-targeted phishing lure entirely (Trend Micro, 2024).
Toolchain and delivery center on a family of custom loaders — HUI Loader (in continuous use since ~2015), the more sophisticated multi-layered Ecipekac loader, ChChes, and FYAnti — that deploy via DLL side-loading against legitimate signed executables, a technique chosen specifically to blend malicious module loading into what endpoint tooling sees as normal process activity. These loaders deliver a rotating set of backdoors: PlugX and RedLeaves historically, UPPERCUT/ANEL and SodaMaster in the A41APT era, and LODEINFO paired with the NOOPDOOR secondary implant in current Earth Kasha-cluster operations. LODEINFO functions as the primary, feature-rich backdoor (shellcode execution, keylogging, screen capture, file exfiltration); NOOPDOOR — which shares code lineage with ANEL — is deployed as a lower-profile secondary implant specifically to preserve access if the primary backdoor is discovered, and has been observed maintaining persistence for two to three years in a single victim environment (Trend Micro, 2024).
Post-compromise tradecraft leans heavily on dual-use and living-off-the-land tooling once inside a network: Mimikatz and pwdump for credential access, AdFind for Active Directory reconnaissance, and Impacket/PsExec alongside native RDP and SSH for lateral movement — all chosen because they are difficult to distinguish from legitimate administrator activity, especially inside an MSP's own management infrastructure where such tools are expected to be present. Cobalt Strike has been observed delivered via the HUI Loader chain as a COTS force-multiplier for later-stage operations. Command and control infrastructure mixes actor-registered domains with a smaller proportion of Dynamic DNS domains (Palo Alto Unit 42), and exfiltration is conducted over the same backdoor C2 channel rather than a separate dedicated exfil path — consistent with an operational preference for minimizing distinct, separately-detectable infrastructure footprints across a long-dwell-time campaign.
output/vulns/ library (current roster: Heartbleed, Spectre/Meltdown, PaperCut, PrintNightmare, Rockwell Logix Auth Bypass, WatchGuard Firebox Auth Bypass, SonicWall SonicOS Access Control, Chrome WebGL OOB Write — none match). Stated as an open gap rather than a fabricated cross-reference.| Type | Value / Description | Source | Date |
|---|---|---|---|
| CVE | CVE-2023-28461 — Array Networks AG SSL-VPN, exploited for initial access | Trend Micro | 2023 |
| CVE | CVE-2023-45727 — Proself file-transfer appliance, exploited for initial access | Trend Micro | 2023 |
| CVE | CVE-2023-27997 — FortiOS/FortiProxy, exploited for initial access | Trend Micro | 2023 |
| CVE | CVE-2013-3900 — WinVerifyTrust signature-validation abuse, used by LODEINFOLDR to hide encrypted payload inside a legitimate digital signature | Trend Micro | 2024 |
| MALWARE | LODEINFO, NOOPDOOR/NOOPLDR, PlugX, HUI Loader, Ecipekac, ChChes, RedLeaves, SNUGRIDE, BUGJUICE, HAYMAKER, UPPERCUT/ANEL, SodaMaster, P8RAT, FYAnti (family names — specific current sample hashes not independently verified in this research pass) | MITRE ATT&CK / Multiple Vendors | 2017–2025 |
| INFRA | C2 infrastructure documented as a mix of actor-registered domains and a smaller proportion of Dynamic DNS domains — specific current domain values not independently reproduced in this card | Palo Alto Unit 42 | 2017 |
| NOTE | No specific current file hashes, C2 domains, or IP addresses were independently verified firsthand during this research pass. Vendor playbooks (notably Palo Alto Unit 42's "menuPass Playbook and IOCs") publish detailed hash/domain appendices — consult those directly for operational blocklisting rather than treating the malware-family names above as sufficient detection signal on their own. | Analyst Note | 2026-09-04 |
menuPass earns a CRITICAL threat-level assessment on the strength of demonstrated impact rather than novelty: Operation Cloud Hopper remains one of the highest-leverage espionage campaigns ever publicly documented, precisely because compromising a single MSP granted access to dozens of downstream victims who had implemented no failure of their own. That access model — not any single piece of malware — is the group's most dangerous capability, and it generalizes to any organization that outsources IT administration to a third party with standing privileged access.
The most significant open question this assessment cannot resolve with available public sourcing is the precise organizational relationship between the core, DOJ-indicted menuPass identity and the newer Earth Kasha/APT10-Umbrella cluster responsible for 2023–2025 LODEINFO/NOOPDOOR activity against Japan and Taiwan. Trend Micro — the vendor with the deepest visibility into this specific cluster — explicitly states it does not have sufficient evidence to fully confirm the two are the same operational unit, describing them instead as related but analytically distinct within a broader "APT10 Umbrella." This card follows that same caution: claims specific to core menuPass (Cloud Hopper, the DOJ indictment, PlugX/HUI Loader/Ecipekac tradecraft) are held at [HIGH] confidence; claims specific to the Earth Kasha cluster's CVE-driven initial access and LODEINFO/NOOPDOOR tooling are held at [MEDIUM] confidence for their linkage to the core identity, even though the tooling lineage (shared code with ANEL/UPPERCUT) and consistent Japan-centric targeting doctrine make some relationship highly plausible. What would raise this to [HIGH]: a government attribution statement or DOJ filing explicitly naming Earth Kasha activity as menuPass/APT10, analogous to the 2018 indictment's treatment of Cloud Hopper.
Forward risk trajectory is upward, not stable. The 2023 pivot from spearphishing toward direct SSL-VPN/file-storage appliance exploitation is a rational adaptation — it removes dependency on a human clicking a malicious attachment and instead exploits scanning-detectable but often unpatched edge infrastructure, a pattern now common across multiple Chinese state-linked operators. Any organization running Array Networks AG, Proself, or FortiOS/FortiProxy infrastructure with unpatched instances of the associated 2023 CVEs should treat menuPass/Earth-Kasha-umbrella activity as a live, not historical, risk — particularly given documented 2–3 year dwell times once NOOPDOOR achieves persistence.