APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
ID: cc3a0151-83d2-4324-a178-a0426c3f22c7
STIX ID: report--cc3a0151-83d2-4324-a178-a0426c3f22c7
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2019-02-06
Last Modified Date: 2019-02-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future and Rapid7 detail a sustained APT10 (Chinese state-sponsored) cyberespionage campaign against a Norwegian MSP (Visma), a U.S. law firm, and an international apparel company between late 2017 and 2018; attackers used stolen Citrix/remote-access credentials, DLL sideloading to deploy Trochilus and UPPERCUT implants, Mimikatz to harvest credentials and NTDS.DIT, and exfiltrated proprietary data to Dropbox — the report includes full malware analysis, IoCs (IPs, domains, hashes, filenames), timeline, attribution evidence, and mitigation guidance.
