logo

APT10__2017__cloud-hopper-report-final-upda_72977.pdf

ID: 92971b16-733e-4787-8e4a-c8682d6072e2

STIX ID: report--92971b16-733e-4787-8e4a-c8682d6072e2

Threat Score

92/100

Uploaded: 2026-08-07

Published Date: 2017-04-03

Last Modified Date: 2017-04-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC/BAE Systems report exposes Operation Cloud Hopper, a large-scale APT10 campaign that targeted managed IT service providers to gain broad access to client networks and exfiltrate sensitive IP; it also documents a parallel Japan-focused campaign using ChChes. The report includes timelines, malware families (Poison Ivy, PlugX, ChChes, Quasar, RedLeaves), detailed TTPs (spearphishing, credential theft, RDP/Robocopy/PSCP exfiltration), dynamic-DNS C2 infrastructure and IOCs, and assesses APT10 as a highly capable China-aligned espionage actor.