Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT10

🇨🇳APT10

🇨🇳 APT10 is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 26 detection use cases to this actor across 60 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-02-26 to 2026-02-26.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0045) ↗
26Use cases
1Articles
60Techniques
5IOCs

Known aliases

APT10Stone PandaMenuPassCloudhopperPotassiumBronze RiversidemenuPassCicadaPOTASSIUMRed ApolloCVNXHOGFISHBRONZE RIVERSIDE

Top techniques

All other tracked techniques

T1003.002 · Security Account ManagerT1003.003 · NTDST1003.004 · LSA SecretsT1005 · Data from Local SystemT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.004 · SSHT1027.013 · Encrypted/Encoded FileT1036 · MasqueradingT1036.003 · Rename Legitimate UtilitiesT1036.005 · Match Legitimate Resource Name or LocationT1039 · Data from Network Shared DriveT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055.012 · Process HollowingT1056.001 · KeyloggingT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.003 · Clear Command HistoryT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1074.001 · Local Data StagingT1074.002 · Remote Data StagingT1078 · Valid AccountsT1083 · File and Directory DiscoveryT1087.002 · Domain AccountT1090.002 · External ProxyT1105 · Ingress Tool TransferT1106 · Native APIT1119 · Automated CollectionT1127.001 · MSBuildT1140 · Deobfuscate/Decode Files or InformationT1199 · Trusted RelationshipT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1210 · Exploitation of Remote ServicesT1218 · System Binary Proxy ExecutionT1218.004 · InstallUtilT1547.001 · Registry Run Keys / Startup FolderT1553.002 · Code SigningT1560 · Archive Collected DataT1560.001 · Archive via UtilityT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1568.001 · Fast Flux DNST1573.002 · Asymmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1583.001 · DomainsT1588.002 · Tool

Detection use cases (26)

APT10 / MenuPass DLL sideloading: signed host EXE pairing with trojanised sibling DLL from user-writable path (LODEINFO / ANEL / PlugX) AI · profile SΣDD APT10 / Cloud Hopper MSP-style RDP fan-out followed by AD reconnaissance (csvde / adfind / nltest / net group) AI · profile SΣDD PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke Renamed MSBuild.exe executing inline .csproj from user-writable path Bespoke PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ Bespoke PlugX persistence — Run key 'G DATA' pointing to C:\Users\Public\GDatas\Avk.exe Bespoke PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Trusted vendor binary / installer launching unusual children Internal Network connections to article IPs / domains Internal File hash IOCs — endpoint file/process match Internal 1Password impossible-travel sign-in MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access MITRE match Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes MITRE match Package manager lifecycle hook spawns network-fetching shell or runtime MITRE match Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain MITRE match

Threat-intel articles (1)

Tracked indicators

Domains (5)

decoorat.net decoraat.net gesecole.net onedow.gesecole.net onedown.gesecole.net