Threat Actor ๐จ๐ณ China
APT10
Also known as: STONE PANDA ยท Menupass Team ยท happyyongzi ยท POTASSIUM ยท Red Apollo ยท CVNX ยท HOGFISH ยท Cloud Hopper ยท BRONZE RIVERSIDE ยท ATK41 ยท G0045 ยท Granite Taurus ยท TA429 ยท Cicada ยท Purple Typhoon
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.
Indicators of Compromise 27
Domain 8[.]8[.]8[.]8 Domain decoraat[.]net Domain onedown[.]gesecole[.]net Filename .pkgdb Filename AVK.exe Filename AVKTray.dat Filename Avk.dll Filename Bulbature Filename DriveSwitch Filename Invitation_Letter_No.02_2026.csproj Filename Invitation_Letter_No.02_2026.exe Filename RushDrop Filename SilentRaid Filename busybox Filename chargen Filename daytime SHA-256 29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad SHA-256 46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc SHA-256 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596 SHA-256 5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc SHA-256 6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7 SHA-256 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200 SHA-256 7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b176 SHA-256 8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99 SHA-256 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d SHA-256 d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e SHA-256 de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1
MITRE ATT&CK TTPs 19
T1021.001 T1027 T1036 T1036.005 T1055 T1055.001 T1057 T1059.001 T1059.003 T1071.001 T1082 T1083 T1090 T1105 T1124 T1133 T1204.002 T1566 T1566.001
Remote Desktop Protocol
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Masquerading
Defense Evasion
Match Legitimate Name or Location
Defense Evasion
Process Injection
Defense Evasion
Dynamic-link Library Injection
Defense Evasion
Process Discovery
Discovery
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
System Time Discovery
Discovery
External Remote Services
Persistence
Malicious File
Execution
Phishing
Initial Access
Spearphishing Attachment
Initial Access
Source Articles
UAT-7290 targets high value telecommunications infrastructure in South Asia
Cisco Talos has identified a sophisticated China-nexus APT group tracked as UAT-7290, active since at least 2022, targeting high-value telecommunications infrastructure in South Asia and recently expanding into Southeastern Europe. The group conducts espionage and establishes Operational Relay Box (ORB) nodes using a suite of custom and open-source malware, including RushDrop, DriveSwitch, SilentRaid, and Bulbature. UAT-7290 leverages one-day exploits, SSH brute-forcing, and publicly available proof-of-concept code to compromise edge devices and gain initial access. Technical overlaps with APT10 and Red Foxtrot, as well as shared infrastructure and malware traits, suggest ties to Chinese state-sponsored actors.
static-urls
PlugX Meeting Invitation via MSBuild and GDATA
A recent PlugX RAT campaign leverages a spear-phishing email with the subject 'Meeting Invitation' to deliver malicious payloads via DLL side-loading. The infection chain uses a legitimate G DATA antivirus executable (Avk.exe) to load a malicious DLL (Avk.dll), which decrypts and executes the payload from AVKTray.dat. The malware establishes persistence through a registry Run key and communicates with the C2 server at decoorat[.]net over HTTPS on port 443. The campaign demonstrates continued use of trusted binaries, XOR-based obfuscation, and API hashing techniques consistent with China-aligned threat actors.
lab52 ยท6mo ago