logo

APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign

ID: 781f61cb-684f-47ca-8ad4-14c573200d84

STIX ID: report--781f61cb-684f-47ca-8ad4-14c573200d84

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2019-02-12

Last Modified Date: 2019-02-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future (Insikt Group) and Rapid7 describe a sustained APT10 (Chinese MSS‑linked) cyberespionage campaign that compromised a Norwegian MSP (Visma), a U.S. law firm, and an international apparel company via stolen Citrix/remote‑access credentials. Attackers used DLL sideloading to deploy a Trochilus variant (with XOR/RC4/Salsa20 layers) and UPPERCUT, stole credentials with Mimikatz, harvested Active Directory data (NTDS.DIT), and exfiltrated sensitive files to Dropbox using renamed WinRAR and cURL; the report includes technical malware analysis, C2/infrastructure details, and defensive recommendations.