logo

APT10__2017__PWC_cloud-hopper-report-final-v4_04-03-2017.pdf

ID: d60191bc-c049-4c09-b9d2-83457309b6c3

STIX ID: report--d60191bc-c049-4c09-b9d2-83457309b6c3

Threat Score

95/100

Uploaded: 2026-08-07

Published Date: 2017-04-04

Last Modified Date: 2017-04-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Cloud Hopper: a PwC UK and BAE Systems investigation attributing a large, sustained espionage campaign to APT10 (China-aligned). The campaign compromises managed IT service providers (MSPs) to gain broad access to MSP customers, uses bespoke and modified malware (PlugX, ChChes, Quasar, RedLeaves), dynamic DNS-based C2 infrastructure, credential theft and lateral movement techniques, and has resulted in large-scale targeted data exfiltration and numerous IOCs for detection and remediation.