menuPass
MITRE ATT&CK: G0045 View on attack.mitre.org
Aliases: Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE, STONE PANDA, Menupass Team, happyyongzi, Cloud Hopper, ATK41, Granite Taurus, TA429, Purple Typhoon, menuPass, GOLEM, Evilgrab, AEON, LIVESAFE, ChChes, Haymaker, Webmonder, Foxtrot, Foxmail, MenuPass
- First seen
- 2006-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 5 (5 malicious)
- Last IoC activity
- 2026-09-01 20:32:53
- Profile updated
- 2026-07-07 12:32:15
Targeted industries: defense-and-aerospace energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications education-and-nonprofits
Targeted regions: country_code:jp country_code:cn
Context
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company. menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.
Recent IoC activity
5 malicious indicators in Maltiverse are attributed to menuPass (G0045). The 5 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | microsofts.com | 2026-09-03 | 1 |
| hostname | microupdate.xyz | 2026-07-28 | 2 |
| hostname | duckducklive.top | 2026-07-22 | 3 |
| file sample | AdventureQuest.exe | 2026-07-04 | 3 |
| hostname | encentchat.net | 2025-12-24 | 1 |
Detection coverage
- 178 YARA rules
- 822 Sigma rules
Malware & tools used
- Remote System Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Masquerading (attack-pattern)
- File Deletion (attack-pattern)
- Network Service Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Archive via Utility (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Tool (attack-pattern)
- Malicious File (attack-pattern)
- External Proxy (attack-pattern)
- Valid Accounts (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Fast Flux DNS (attack-pattern)
- Rename Legitimate Utilities (attack-pattern)
- Keylogging (attack-pattern)
- Domain Account (attack-pattern)
- NTDS (attack-pattern)
- InstallUtil (attack-pattern)
- Native API (attack-pattern)
- Security Account Manager (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Trusted Relationship (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
Reports & references
- Mandiant — Apt Groups (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- ncsc.gov.uk — Joint%20Report%20On%20Publicly%20Available%20Hacking%20Tools%20%28Ncsc%29 (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Palo Alto Unit 42 — Unit42 Menupass Returns New Malware New Attacks Japanese Academics Organizations (report)
- cfr.org — Apt 10 (report)
- pwc.co.uk — Cloud Hopper Report Final V4 (report)
- Mandiant — Apt10 Menupass Grou (report)
- eweek.com — Chinese Nation State Hackers Target U.S In Operation Tradesecret (report)
- Trend Micro — Chessmaster Cyber Espionage Campaign (report)
- accenture.com — Accenture Hogfish Threat Analysis (report)
- us-cert.gov — Ir Alert Med 17 093 01C Intrusions Affecting Multiple Victims Across Multiple Sectors (report)
- Mandiant — Apt10 Targeting Japanese Corporations Using Updated Ttps (report)
- fbi.gov — Chinese Hackers Indicted 122018 (report)
- MITRE ATT&CK — G0045 (report)
- secureworks.com — Bronze Riverside (report)
- Palo Alto Unit 42 — Granite Taurus (report)
- proofpoint.com — Ta410 Group Behind Lookback Attacks Against Us Utilities Sector Returns New (report)
- CrowdStrike — Two Birds One Stone Panda (report)
- Broadcom/Symantec — Cicada Apt10 China Ngo Government Attacks (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- researchcenter.paloaltonetworks.com — Unit42 Menupass Returns New Malware New Attacks Japanese Academics Organizations (report)
- web.archive.org — Accenture Hogfish Threat Analysis (report)
- Broadcom/Symantec — Cicada Apt10 Japan Espionage (report)
External references
- mitre-attack — G0045
- HOGFISH
- POTASSIUM
- Stone Panda
- APT10
- menuPass
- Red Apollo
- CVNX
- BRONZE RIVERSIDE
- Cicada
- Accenture Hogfish April 2018
- SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022
- Crowdstrike CrowdCast Oct 2013
- FireEye APT10 April 2017
- FireEye Poison Ivy
- FireEye APT10 Sept 2018
- Palo Alto menuPass Feb 2017
- PWC Cloud Hopper April 2017
- Symantec Cicada November 2020
- DOJ APT10 Dec 2018