Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE
46
techniques
25
software
11,366
corpus matches
profile
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.
menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.
techniques
46 attributed · most-instrumented first
software
25 malware & tools attributed
Mimikatz
S0002
pwdump
S0006
PoisonIvy
S0012
PlugX
S0013
PsExec
S0029
Net
S0039
Ping
S0097
cmd
S0106
ChChes
S0144
EvilGrab
S0152
read this carefully
11,366 corpus matches is not attribution
That count is indicators which exhibit techniques menuPass is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+34 more techniques
RedLeaves
S0153
Cobalt Strike
S0154
SNUGRIDE
S0159
certutil
S0160
PowerSploit
S0194
QuasarRAT
S0262
UPPERCUT
S0275
Impacket
S0357
esentutl
S0404
AdFind
S0552
Ecipekac
S0624
P8RAT
S0626
SodaMaster
S0627
FYAnti
S0628
HUI Loader
S1097
showing 30 of 11,366
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.