menuPass

MITRE ATT&CK: G0045 View on attack.mitre.org

Aliases: Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE, STONE PANDA, Menupass Team, happyyongzi, Cloud Hopper, ATK41, Granite Taurus, TA429, Purple Typhoon, menuPass, GOLEM, Evilgrab, AEON, LIVESAFE, ChChes, Haymaker, Webmonder, Foxtrot, Foxmail, MenuPass

First seen
2006-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
5 (5 malicious)
Last IoC activity
2026-09-01 20:32:53
Profile updated
2026-07-07 12:32:15

Targeted industries: defense-and-aerospace energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications education-and-nonprofits

Targeted regions: country_code:jp country_code:cn

Context

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company. menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.

Recent IoC activity

5 malicious indicators in Maltiverse are attributed to menuPass (G0045). The 5 most recently updated:

TypeIndicatorUpdatedSources
hostname microsofts.com 2026-09-03 1
hostname microupdate.xyz 2026-07-28 2
hostname duckducklive.top 2026-07-22 3
file sample AdventureQuest.exe 2026-07-04 3
hostname encentchat.net 2025-12-24 1

Detection coverage

  • 178 YARA rules
  • 822 Sigma rules

Malware & tools used

  • Remote System Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Masquerading (attack-pattern)
  • File Deletion (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Tool (attack-pattern)
  • Malicious File (attack-pattern)
  • External Proxy (attack-pattern)
  • Valid Accounts (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Fast Flux DNS (attack-pattern)
  • Rename Legitimate Utilities (attack-pattern)
  • Keylogging (attack-pattern)
  • Domain Account (attack-pattern)
  • NTDS (attack-pattern)
  • InstallUtil (attack-pattern)
  • Native API (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Trusted Relationship (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)

Reports & references

  • Mandiant — Apt Groups (report)
  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • ncsc.gov.uk — Joint%20Report%20On%20Publicly%20Available%20Hacking%20Tools%20%28Ncsc%29 (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • Palo Alto Unit 42 — Unit42 Menupass Returns New Malware New Attacks Japanese Academics Organizations (report)
  • cfr.org — Apt 10 (report)
  • pwc.co.uk — Cloud Hopper Report Final V4 (report)
  • Mandiant — Apt10 Menupass Grou (report)
  • eweek.com — Chinese Nation State Hackers Target U.S In Operation Tradesecret (report)
  • Trend Micro — Chessmaster Cyber Espionage Campaign (report)
  • accenture.com — Accenture Hogfish Threat Analysis (report)
  • us-cert.gov — Ir Alert Med 17 093 01C Intrusions Affecting Multiple Victims Across Multiple Sectors (report)
  • Mandiant — Apt10 Targeting Japanese Corporations Using Updated Ttps (report)
  • fbi.gov — Chinese Hackers Indicted 122018 (report)
  • MITRE ATT&CK — G0045 (report)
  • secureworks.com — Bronze Riverside (report)
  • Palo Alto Unit 42 — Granite Taurus (report)
  • proofpoint.com — Ta410 Group Behind Lookback Attacks Against Us Utilities Sector Returns New (report)
  • CrowdStrike — Two Birds One Stone Panda (report)
  • Broadcom/Symantec — Cicada Apt10 China Ngo Government Attacks (report)
  • secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • researchcenter.paloaltonetworks.com — Unit42 Menupass Returns New Malware New Attacks Japanese Academics Organizations (report)
  • web.archive.org — Accenture Hogfish Threat Analysis (report)
  • Broadcom/Symantec — Cicada Apt10 Japan Espionage (report)

External references