Stone Panda, APT 10, menuPass

Description

menuPass is a threat group that appears to originate from China and has been active since approximately 2009. The group has targeted healthcare, defense, aerospace, and government sectors, and has targeted Japanese victims since at least 2014. In 2016 and 2017, the group targeted managed IT service providers, manufacturing and mining companies, and a university.

Also see Operation LiberalFace, MirrorFace and Twisted Panda.

Names

NameName-Giver
Stone PandaCrowdStrike
APT 10Mandiant
menuPass TeamSymantec
menuPassPalo Alto
Red ApolloPWC
CVNXBAE Systems
PotassiumMicrosoft
HogfishiDefense
HappyyongziFireEye
CicadaSymantec
Bronze RiversideSecureWorks
CTG-5938SecureWorks
ATK 41Thales
TA429Proofpoint
ITG01IBM
Granite TaurusPalo Alto
Earth KashaTrend Micro
Cuckoo SpearCybereason
Purple TyphoonMicrosoft

Country

State-sponsored, Tianjin bureau of the Chinese Ministry of State Security, Huaying Haitai

Motivation

  • Information theft and espionage

First Seen

2006

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

2aa9ca75-fa1b-422e-9677-02983934f983

Last Card Change

2025-06-28