APT10__2018__msp_investigation_report.pdf
ID: 0b5487cf-f729-4002-95b0-47228afa56a2
STIX ID: report--0b5487cf-f729-4002-95b0-47228afa56a2
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2018-12-14
Last Modified Date: 2018-12-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Australian Cyber Security Centre investigated a 2016–2017 compromise of a multinational construction services company's Australian arm via a legitimately provisioned MSP account; the actor (linked to APT10/Operation Cloud Hopper) installed PlugX and later RedLeaves RATs, collected Active Directory data (including an NTDS export), used Mimikatz, maintained persistence across domain controllers and exfiltrated commercial data, with the report providing technical findings and mitigation guidance.
