Threat actor · all actors
menuPassG0045 state
🇨🇳 CN · MSS · Tianjin Bureau
aka menuPass, Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE, Menupass Team, happyyongzi, Cloud Hopper, ATK41, G0045, Granite Taurus, TA429, Purple Typhoon
Last updated: 2026-08-22
About this actor
[menuPass](https://attack.mitre.org/groups/G0045) is a threat group that has been active since at least 2006. Individual members of [menuPass](https://attack.mitre.org/groups/G0045) are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018) [menuPass](https://attack.mitre.org/groups/G0045) has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.(Citation: Palo Alto menuPass Feb 2017)(Citation: Crowdstrike CrowdCast Oct 2013)(Citation: FireEye Poison Ivy)(Citation: PWC Cloud Hopper April 2017)(Citation: FireEye APT10 April 2017)(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
Secureworkscolour-metal names
Palo Alto Unit 42constellation names
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 65 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2021 — 1 CVE published
- 2017 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2017-6328 | 6.9 | 8.8 | 0.0214 | 2017-08-11 | see CVE |
CVE-2020-6789 | 5.8 | 7.8 | 0.0035 | 2021-03-25 | see CVE |
T1003OS Credential Dumping ↗T1003.002Security Account Manager ↗T1003.003NTDS ↗T1003.004LSA Secrets ↗T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.004SSH ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.003Rename Legitimate Utilities ↗T1036.005Match Legitimate Resource Name or Location ↗T1039Data from Network Shared Drive ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1055.012Process Hollowing ↗T1056Input Capture ↗T1056.001Keylogging ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1070Indicator Removal ↗T1070.003Clear Command History ↗T1070.004File Deletion ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1074.002Remote Data Staging ↗T1078Valid Accounts ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1090.002External Proxy ↗T1105Ingress Tool Transfer ↗T1106Native API ↗T1119Automated Collection ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1199Trusted Relationship ↗T1204User Execution ↗T1204.002Malicious File ↗T1210Exploitation of Remote Services ↗T1218System Binary Proxy Execution ↗T1218.004InstallUtil ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1568Dynamic Resolution ↗T1568.001Fast Flux DNS ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 45 / 65 | 69% |
CM-6 | 41 / 65 | 63% |
CM-2 | 37 / 65 | 57% |
SI-3 | 36 / 65 | 55% |
AC-3 | 29 / 65 | 45% |
AC-6 | 29 / 65 | 45% |
CM-7 | 29 / 65 | 45% |
AC-2 | 27 / 65 | 42% |
CA-7 | 24 / 65 | 37% |
SI-7 | 21 / 65 | 32% |
AC-5 | 20 / 65 | 31% |
CM-5 | 19 / 65 | 29% |
SC-7 | 19 / 65 | 29% |
IA-2 | 18 / 65 | 28% |
RA-5 | 18 / 65 | 28% |
Co-occurring actors
- APT41 2 shared CVEs
- APT19 2 shared CVEs
- Winnti Group 2 shared CVEs
- Deep Panda 2 shared CVEs
- APT1 2 shared CVEs
- Leviathan 2 shared CVEs
- APT3 2 shared CVEs
Similar actors
Similar TTPs
- Threat Group-3390 0.42
- GALLIUM 0.39
- APT39 0.37
- MirrorFace 0.37
- Silence 0.37
Overlapping CVEs
- APT1 1.00
- Deep Panda 1.00
- APT3 1.00
- Winnti Group 1.00
- APT41 1.00
Active in same years
- APT1 2.00
- Deep Panda 2.00
- APT3 2.00
- Lazarus Group 2.00
- Winnti Group 2.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00