All actors

menuPass

Also reported as Red Apollo, Cicada, POTASSIUM, APT10, CVNX and 32 other names. Linked to China by four sources.

Reports
1,159
Last reported
Known CVEs
458
Techniques in ATT&CK
46
Origin
China
ID
G0045
Merge evidence
46 alias matches

Reports per quarter

  1. 2011 Q2: 1 report
  2. 2011 Q3: no reports
  3. 2011 Q4: no reports
  4. 2012 Q1: no reports
  5. 2012 Q2: no reports
  6. 2012 Q3: no reports
  7. 2012 Q4: no reports
  8. 2013 Q1: 1 report
  9. 2013 Q2: no reports
  10. 2013 Q3: 1 report
  11. 2013 Q4: 2 reports
  12. 2014 Q1: 2 reports
  13. 2014 Q2: no reports
  14. 2014 Q3: 2 reports
  15. 2014 Q4: no reports
  16. 2015 Q1: 2 reports
  17. 2015 Q2: no reports
  18. 2015 Q3: 8 reports
  19. 2015 Q4: 3 reports
  20. 2016 Q1: 2 reports
  21. 2016 Q2: 4 reports
  22. 2016 Q3: 2 reports
  23. 2016 Q4: 1 report
  24. 2017 Q1: 13 reports
  25. 2017 Q2: 19 reports
  26. 2017 Q3: 7 reports
  27. 2017 Q4: 5 reports
  28. 2018 Q1: 12 reports
  29. 2018 Q2: 9 reports
  30. 2018 Q3: 26 reports
  31. 2018 Q4: 9 reports
  32. 2019 Q1: 19 reports
  33. 2019 Q2: 21 reports
  34. 2019 Q3: 10 reports
  35. 2019 Q4: 24 reports
  36. 2020 Q1: 23 reports
  37. 2020 Q2: 35 reports
  38. 2020 Q3: 25 reports
  39. 2020 Q4: 62 reports
  40. 2021 Q1: 57 reports
  41. 2021 Q2: 70 reports
  42. 2021 Q3: 72 reports
  43. 2021 Q4: 61 reports
  44. 2022 Q1: 79 reports
  45. 2022 Q2: 98 reports
  46. 2022 Q3: 63 reports
  47. 2022 Q4: 29 reports
  48. 2023 Q1: 30 reports
  49. 2023 Q2: 15 reports
  50. 2023 Q3: 24 reports
  51. 2023 Q4: 17 reports
  52. 2024 Q1: 15 reports
  53. 2024 Q2: 19 reports
  54. 2024 Q3: 23 reports
  55. 2024 Q4: 16 reports
  56. 2025 Q1: 22 reports
  57. 2025 Q2: 10 reports
  58. 2025 Q3: 11 reports
  59. 2025 Q4: 9 reports
  60. 2026 Q1: 7 reports
  61. 2026 Q2: 59 reports
  62. 2026 Q3: 3 reports
Dated reports, 2011 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 303 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 458 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Bankshot (Malware Family)

    date ORKL added it fromORKL

Show all 1,159 reports Show fewer
  1. StoneDrill (Malware Family)

    date ORKL added it fromORKL

  2. Stone Panda, APT 10, menuPass

    date ORKL added it fromORKL

  3. Oblique RAT (Malware Family)

    date ORKL added it fromORKL

  4. CrowdCasts Monthly: You Have an Adversary Problem

    date ORKL added it fromORKL

  5. METALJACK (Malware Family)

    date ORKL added it fromORKL

  6. elf.wellmess (Malware Family)

    date ORKL added it fromORKL

  7. SUNBURST (Malware Family)

    date ORKL added it fromORKL

  8. Poison Ivy (Malware Family)

    date ORKL added it fromORKL

  9. Nightshade Panda, APT 9, Group 27

    date ORKL added it fromORKL

  10. Red Apollo

    date ORKL added it fromORKL

  11. Council on Foreign Relations

    date ORKL added it fromORKL

  12. MimiKatz (Malware Family)

    date ORKL added it fromORKL

  13. PlugX (Malware Family)

    date ORKL added it fromORKL

  14. PowGoop (Malware Family)

    date ORKL added it fromORKL

  15. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  16. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  17. Quasar RAT (Malware Family)

    date ORKL added it fromORKL

  18. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  19. hodur_recon2024.pdf

    Malpedia library date fromORKL

  20. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  21. Threat Horizons - January 2023

    file creation date Google's Cybersecurity Action Team (GCAT) fromORKL

  22. APT10- Tracking down LODEINFO 2022, part II

    date in the title fromORKL

  23. APT10- Tracking down LODEINFO 2022, part I

    date in the title fromORKL

  24. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  25. RedSense

    Malpedia library date fromORKL

  26. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  27. Space Invaders- Cyber Threats That Are Out Of This World

    date in the title fromORKL

  28. New Qualys Research Report- Evolution of Quasar RAT

    date in the title fromORKL

  29. RedSense

    Malpedia library date fromORKL

  30. CERT-UA

    Malpedia library date fromORKL

  31. CERT-UA

    Malpedia library date fromORKL

  32. CB_941_Canhbao_APT_36c5a857fa.pdf

    Malpedia library date Socialist Republic of Vietnam fromORKLCCS '25 data

  33. BRONZE STARLIGHT Ransomware Operations Use HUI Loader

    date in the title fromORKL

  34. RedSense

    Malpedia library date fromORKL

  35. Phishing Campaigns featuring Ursnif Trojan on the Rise

    date in the title fromORKL

  36. Threat Actors Prey on Eager Travelers

    date in the title fromORKL

  37. eset_threat_report_t12022

    file creation date fromORKL

  38. PowerPoint Presentation

    Malpedia library date Hughes, Jennifer fromORKLCCS '25 data

  39. APT_trends_report_Q2_2022_Securelist

    file creation date fromORKL

  40. Chinese Naikon Group Back with New Espionage Attack

    date in the title fromORKL

  41. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  42. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  43. RedSense

    Malpedia library date fromORKL

  44. Unmasking China’s State Hackers

    date in the title fromORKL

  45. CERT-UA

    Malpedia library date fromORKL

  46. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  47. 2021trends.pdf

    Malpedia library date fromORKL

  48. RedSense

    Malpedia library date fromORKL

  49. Nickel

    Malpedia library date Notice of Pleadings fromORKLCCS '25 data

  50. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  51. EP 103- Cloud Hopper

    date in the title fromORKL

  52. RedSense

    Malpedia library date fromORKL

  53. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  54. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  55. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  56. mtrends-2018.pdf

    file creation date fromORKL

  57. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  58. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  59. CTIR_casestudy_2.pdf

    file creation date fromORKL

  60. CTIR_casestudy_1.pdf

    file creation date fromORKL

  61. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  62. New ICS Threat Activity Group- TALONITE

    date in the title fromORKL

  63. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  64. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  65. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  66. Intezer-2020-Go-Malware-Round-Up.pdf

    Malpedia library date fromORKL

  67. APT10: Tracking down the stealth activity of the A41APT campaign

    file creation date Niwa Yusuke fromORKL

  68. A41APT case ~Analysis of the Stealth APT Campaign Threatening Japan

    Malpedia library date Kaspersky fromORKLCCS '25 data

  69. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  70. China cyber attacks- the current threat landscape

    date in the title fromORKL

  71. Active Directory 侵害と推奨対策

    Malpedia library date fromORKL

  72. From ThreatHunting to Campaign Tracking

    date in the title fromORKL

  73. Attack Activities by Quasar Family

    date in the title fromORKL

  74. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  75. PowerPoint Presentation

    file creation date Ganesan, Brittany (OS/ASA) (CTR) fromORKL

  76. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  77. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  78. TA410

    file creation date fromORKL

  79. BRONZE VINEWOOD Targets Supply Chains _ Secureworks

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  80. BRONZE VINEWOOD Targets Supply Chains

    date in the title fromORKL

  81. P01_P10_eng

    file creation date fromORKL

  82. Deep-dive: The DarkHotel APT

    Malpedia library date Bushido Token fromORKLCCS '25 data

  83. mpressioncss_ta_report_2019_4.pdf

    file creation date fromORKL

  84. 210527.pdf

    Malpedia library date FBI fromORKLCCS '25 data

  85. mpressioncss_ta_report_2019_4

    date in the CCS '25 data Team T5 fromORKLCCS '25 data

  86. Operation Cloud Hopper & RedLeaves

    Malpedia library date LIFARS fromORKLCCS '25 data

  87. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  88. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  89. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  90. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  91. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  92. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  93. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  94. Context Identifies new AVIVORE threat group

    date in the title fromORKL

  95. AVIVORE - Hunting Global Aerospace through the Supply Chain

    date in the CCS '25 data Contextis fromORKLCCS '25 data

  96. Two Birds, One STONE PANDA

    file creation date Crowdstrike fromORKL

  97. APT41: A Dual Espionage and Cyber Crime Operation

    file creation date FireEye fromORKL

  98. report_APT41

    file creation date fromORKL

  99. Is there a pattern-

    date in the title fromORKL

  100. Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers

    date in the CCS '25 data Cybereason fromORKLCCS '25 data

  101. Threat Spotlight_ MenuPass_QuasarRAT Backdoor

    date in the CCS '25 data Cylance fromORKLCCS '25 data

  102. Threat Spotlight- MenuPass-QuasarRAT Backdoor

    date in the title fromORKL

  103. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  104. Uncovering new Activity by APT10

    date in the title fromORKL

  105. Uncovering New Activity By APT10

    date in the CCS '25 data enSilo fromORKLCCS '25 data

  106. APT_trends_report_Q1_2019_Securelist

    file creation date fromORKL

  107. rpt-mtrends-2019.pdf

    file creation date fromORKL

  108. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  109. Attacker Tracking Users Seeking Pakistani Passport

    date in the title fromORKL

  110. rpt-mtrends-2019

    file creation date fromORKL

  111. Defeating Compiler-Level Obfuscations Used in APT10 Malware

    date in the CCS '25 data Carbon Black fromORKLCCS '25 data

  112. APT Groups Moving Down the Supply Chain

    date in the title fromORKL

  113. 2018 Master Table

    file creation date fromORKL

  114. APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign

    date in the CCS '25 data Recorded Future fromORKLCCS '25 data

  115. 2018_ A Year of Cyber Attacks – HACKMAGEDDON

    date in the CCS '25 data Hackmageddon fromORKLCCS '25 data

  116. The APT Chronicles_December 2018 edition

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  117. Cyber-Espionage Campaign Targeting the Naval Industry (“MartyMcFly”)

    date in the CCS '25 data Yoroi fromORKLCCS '25 data

  118. VB2018 - Who Was Not Responsible for Olympic Destroyer

    date in the title fromORKL

  119. APT10 Targeting Japanese Corporations Using Updated TTPs

    file creation date fromORKL

  120. APT10 Targeting Japanese Corporations Using Updated TTPs

    date in the title fromORKL

  121. Who is Mr An, and was he working for APT10-

    date in the title fromORKL

  122. Two Birds, One STONE PANDA

    date in the CCS '25 data IntrusionTruth fromORKLCCS '25 data

  123. Two Birds, One STONE PANDA

    date in the title fromORKL

  124. Chinese Cyberespionage Originating From Tsinghua University Infrastructure

    date in the CCS '25 data Recorded Future fromORKLCCS '25 data

  125. Who is Mr Zhang-

    date in the title fromORKL

  126. Who is Mr Gao-

    date in the title fromORKL

  127. Who is Mr Zheng-

    date in the title fromORKL

  128. BSides IR in Heterogeneous Environment

    Malpedia library date fromORKL

  129. M-TRENDS2018

    file creation date FireEye fromORKL

  130. Hogfish Redleaves Malware Threat Analysis I Accenture

    file creation date fromORKL

  131. ChessMaster Adds Updated Tools to Its Arsenal

    date in the title fromORKL

  132. Who Wasn’t Responsible for Olympic Destroyer-

    date in the title fromORKL

  133. Bitdefender Labs

    Malpedia library date Bitdefender fromORKLCCS '25 data

  134. Advanced Persistent Threat Groups

    date in the title fromORKL

  135. chessmaster-cyber-espionage-campaign

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  136. BfV Cyber-Brief Nr. 2/2017

    file creation date Bundesamt für Verfassungsschutz fromORKL

  137. Coming Soon…

    date in the title fromORKL

  138. Operation Cloud Hopper

    file creation date fromORKL

  139. cloud-hopper-report-final-upda_72977

    file creation date fromORKL

  140. Operation Cloud Hopper

    date in the CCS '25 data PWC fromORKLCCS '25 data

  141. The Deception Project: A New Japanese-Centric Threat

    date in the CCS '25 data Cylance fromORKLCCS '25 data

  142. The Deception Project- A New Japanese-Centric Threat

    date in the title fromORKL

  143. ICIT-Brief-China-Espionage-Dynasty

    date in the CCS '25 data Debra Obyrne fromORKLCCS '25 data

  144. security_report_20160613.pdf

    Malpedia library date fromORKL

  145. The Four Element Sword Engagement

    file creation date Arbor fromORKL

  146. Taiwan Presidential Election: A Case Study on Thematic Targeting

    date in the CCS '25 data PWC fromORKLCCS '25 data

  147. Newcomers in the Derusbi family

    Malpedia library date fromORKL

  148. VB2015_Catching_the_silent_whisper

    Malpedia library date mpun@fortinet.com, ericleung@fortinet.com, ntan@fortinet.com fromORKL

  149. Research, News, and Perspectives

    Malpedia library date fromORKL

  150. HTExploitTelemetry

    Malpedia library date FireEye fromORKLCCS '25 data

  151. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  152. Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx

    date in the CCS '25 data PWC fromORKLCCS '25 data

  153. A Detailed Examination of the Siesta Campaign

    date in the title fromORKL

  154. CrowdCasts Monthly- You Have an Adversary Problem

    date in the title fromORKL

  155. CrowdCasts Monthly: You Have an Adversary Problem

    Malpedia library date fromORKL

  156. 2Q Report on Targeted Attack Campaigns

    file creation date Trend Micro fromORKL

  157. Inside a Back Door Attack

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.