APT10__2017__PWC_cloud-hopper-report-final-v4_04-03-2017.pdf
ID: d60191bc-c049-4c09-b9d2-83457309b6c3
STIX ID: report--d60191bc-c049-4c09-b9d2-83457309b6c3
Threat Score
95/100
Uploaded: 2026-08-07
Published Date: 2017-04-04
Last Modified Date: 2017-04-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Cloud Hopper: a PwC UK and BAE Systems investigation attributing a large, sustained espionage campaign to APT10 (China-aligned). The campaign compromises managed IT service providers (MSPs) to gain broad access to MSP customers, uses bespoke and modified malware (PlugX, ChChes, Quasar, RedLeaves), dynamic DNS-based C2 infrastructure, credential theft and lateral movement techniques, and has resulted in large-scale targeted data exfiltration and numerous IOCs for detection and remediation.
