APT10__2017__cloud-hopper-report-final-upda_72977.pdf
ID: 92971b16-733e-4787-8e4a-c8682d6072e2
STIX ID: report--92971b16-733e-4787-8e4a-c8682d6072e2
Threat Score
92/100
Uploaded: 2026-08-07
Published Date: 2017-04-03
Last Modified Date: 2017-04-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC/BAE Systems report exposes Operation Cloud Hopper, a large-scale APT10 campaign that targeted managed IT service providers to gain broad access to client networks and exfiltrate sensitive IP; it also documents a parallel Japan-focused campaign using ChChes. The report includes timelines, malware families (Poison Ivy, PlugX, ChChes, Quasar, RedLeaves), detailed TTPs (spearphishing, credential theft, RDP/Robocopy/PSCP exfiltration), dynamic-DNS C2 infrastructure and IOCs, and assesses APT10 as a highly capable China-aligned espionage actor.
