APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
ID: 781f61cb-684f-47ca-8ad4-14c573200d84
STIX ID: report--781f61cb-684f-47ca-8ad4-14c573200d84
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2019-02-12
Last Modified Date: 2019-02-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future (Insikt Group) and Rapid7 describe a sustained APT10 (Chinese MSS‑linked) cyberespionage campaign that compromised a Norwegian MSP (Visma), a U.S. law firm, and an international apparel company via stolen Citrix/remote‑access credentials. Attackers used DLL sideloading to deploy a Trochilus variant (with XOR/RC4/Salsa20 layers) and UPPERCUT, stole credentials with Mimikatz, harvested Active Directory data (NTDS.DIT), and exfiltrated sensitive files to Dropbox using renamed WinRAR and cURL; the report includes technical malware analysis, C2/infrastructure details, and defensive recommendations.
