APT10

THREAT ACTOR PROFILE

APT10

APT10

APT10

Stone Panda

APT10 is a China-nexus cyber-espionage group operating since around 2006, likely sponsored by the Ministry of State Security. It is best known for Operation Cloud Hopper, compromising managed service providers to reach downstream victims, and it continues to target technology, government and defense sectors, with a sustained focus on Japan through the LODEINFO and NOOPDOOR malware families.

China

Government / Technology / Defense

First seen

2006

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

APT10, Stone Panda and MenuPass

APT10 is tracked under a long list of vendor names. It maps to one entry among the nation-state actors we document, and its China-nexus espionage overlaps with crews like APT41.

-

-

-

GROUP PROFILE

MSP compromise and long-term espionage

APT10 is a mature China-nexus espionage actor. Its defining tactic is reaching targets indirectly, compromising service providers and trusted software to access many downstream organizations at once, aimed at intellectual-property theft and intelligence collection.

Our record places its origin as China and ties it to espionage across technology, government and defense sectors. The group remains active against Japanese entities through the Cuckoo Spear campaign and the NOOPDOOR and NOOPLDR malware.

Its tradecraft relies on spearphishing, DLL side-loading and fileless techniques, with LODEINFO delivered through malicious Word documents and a deep roster of custom and commodity backdoors.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

MSP and phishing access into custom backdoors

The stages below come from APT10 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

LODEINFO, NOOPDOOR and a deep backdoor set

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Supply-chain and phishing access over software exploitation

APT10's intrusions in our records center on MSP and supply-chain compromise, spearphishing and DLL side-loading rather than on a consistent set of exploited software flaws. Older activity used an Adobe Flash flaw (CVE-2013-0634) in the FHAPPI campaign, but current operations are access- and malware-led, so detection should focus on the LODEINFO document chain and the NOOPDOOR loader behavior.

APT10

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

APT10

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

APT10

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

APT10

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Cloud Hopper, Cuckoo Spear and LODEINFO

Recent reporting tracks the group's long history and current Japan focus.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

APT10

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

APT10

IOC set, full IP, host and hash history.