onlinesyscfg.research
utc
syscfg://research
home/research/apt10-cloud-hopper-operation-global-msp
PublishedNation-State Operations

APT10 Cloud Hopper: How China Compromised 45 MSPs to Reach Hundreds of Their Clients Simultaneously

2026-08-09-16 min read
#apt10#cloud-hopper#china#mss#msp#supply-chain#espionage#plugx#redleaves#made-in-china-2025#third-party-risk

Between 2016 and 2018, Chinese state hackers ran the most systematically ambitious espionage operation against Western commercial targets that had been publicly documented to that point. APT10, a group attributed to China's Ministry of State Security, compromised at least 45 managed service providers (MSPs) across 12 countries. The MSPs were not the targets - they were the means of access. Through the compromised MSPs, APT10 reached the intellectual property, business strategies, and confidential information of hundreds of client organizations across aerospace, defense, automotive, electronics, pharmaceuticals, manufacturing, satellites, and financial services. The operation was called Cloud Hopper.

The MSP targeting strategy was the architectural innovation that made Cloud Hopper distinct. Managed service providers maintain privileged, persistent access to their clients' networks by design - that is what clients pay for. By compromising the MSP, APT10 obtained that pre-built, trusted access to every client the MSP served. One intrusion created a springboard to hundreds of targets. The trust relationship that makes MSPs valuable to their clients made MSPs dangerous as a lateral access point when compromised.

The Attack Chain

APT10's initial access methodology in Cloud Hopper relied heavily on spear-phishing. Targeted employees at MSPs received emails with malicious attachments or links; the resulting malware established a foothold in the MSP's own environment. From there, APT10 used the MSP's legitimate administrative tools and credentials to pivot into client environments. Because the access looked like normal MSP management activity - using the MSP's own tools, from the MSP's own IP space, with the MSP's own credentials - it was extremely difficult for client organizations to distinguish malicious activity from routine MSP administration.

Once inside client environments, APT10 conducted targeted exfiltration focused on intellectual property: technical designs, manufacturing specifications, business plans, and contract information. The group demonstrated significant patience - maintaining access over months or years rather than conducting rapid mass exfiltration. In some cases, APT10 maintained presence inside client networks for years before detection.

[TECHNICAL NOTE]
APT10's toolset in Cloud Hopper included several custom malware families. PlugX was their standard Remote Access Trojan - a modular backdoor with extensive post-exploitation capabilities that had been in use across Chinese APT operations since at least 2012. RedLeaves was a newer tool custom-developed for Cloud Hopper operations, a sophisticated backdoor using DLL side-loading for execution and encrypted C2 communication. QuasarRAT appeared in some intrusions. The group also made heavy use of legitimate Windows administration tools - certutil, PowerShell, net.exe, WMI - for reconnaissance, lateral movement, and credential harvesting. This "living off the land" (LotL) technique made their activity harder to distinguish from legitimate administrator behavior. The combination of custom backdoors for persistence and legitimate tools for operations became a defining characteristic of sophisticated Chinese APT operations throughout the 2016-2020 period, directly contributing to the development of behavioral detection approaches in enterprise security because signature-based detection of LotL techniques is inherently limited.

Scale and Attribution

US and UK joint indictments in December 2018 charged two Chinese nationals, Zhu Hua and Zhang Shilong, as members of APT10 operating under the name Huaying Haitian Science and Technology Co., Ltd. - a front company with ties to the Tianjin Bureau of the MSS. The indictment listed 45 MSPs compromised across 12 countries, with victim industries spanning the full breadth of China's strategic industrial priorities as laid out in the Made in China 2025 plan.

The US, UK, Australia, Canada, Japan, and New Zealand issued coordinated attribution statements simultaneously - the first major multilateral attribution of a Chinese cyber espionage campaign. This coordinated approach reflected lessons learned from years of single-country attributions that China had been able to deflect diplomatically; presenting a unified allied front made dismissal harder and signaled that multiple intelligence services had independently reached the same conclusions.

[WARNING]
Cloud Hopper exposed a fundamental structural vulnerability in enterprise security architecture that extends well beyond APT10. The security model of most organizations implicitly trusts their managed service providers: the MSP is given privileged access because that access is necessary to provide the service, and organizations assume the MSP's security posture is adequate. But an organization's security is therefore bounded by the weakest link in its supply chain of trusted service providers - not just direct vendors but the vendors' vendors. The Cloud Hopper indictment documented compromise vectors where APT10 reached a target organization through not just one but two intermediaries: compromising an MSP's own service provider to reach the MSP, then using the MSP's access to reach the client. This recursive supply chain trust problem - the fact that trusted third-party access is inherently difficult to monitor and restrict - is the same structural problem that SolarWinds (2020) and Kaseya (2021) later exploited. Cloud Hopper predated both and provided the initial large-scale documented case of systematic MSP-as-vector espionage.

Made in China 2025 and Strategic Context

Chinese industrial policy context is essential to understanding Cloud Hopper's target selection. China's Made in China 2025 plan, announced in 2015, identified ten strategic industries for Chinese development and global competitiveness: advanced information technology, automated machine tools and robotics, aerospace and aeronautical equipment, maritime engineering and shipping, advanced rail equipment, energy-saving vehicles and electric vehicles, power equipment, agricultural equipment, new materials, and biopharmaceuticals. The APT10 victim list mapped almost exactly onto these sectors. The espionage was not opportunistic; it was targeted collection against the specific commercial and technological domains China's government had publicly identified as strategic priorities.

This pattern of state-directed IP theft aligned with national industrial strategy - using espionage to accelerate domestic industrial capability in targeted sectors - had been documented since the Mandiant APT1 report in 2013 but Cloud Hopper demonstrated its continued scale and sophistication five years after APT1 was publicly exposed. The 2018 indictments were partly designed to impose reputational and economic costs on this strategy by making the intelligence collection-industrial policy connection explicit and public.

[IOC]
APT10 Cloud Hopper summary: active period approximately 2014-2018, primary activity wave 2016-2018. Attribution: APT10, Stone Panda, MenuPass; attributed to China Ministry of State Security (MSS) Tianjin Bureau. Indicted: Zhu Hua and Zhang Shilong (US DOJ indictment, December 2018); front company Huaying Haitian Science and Technology Co., Ltd. Compromised MSPs: 45+ across 12 countries (US, UK, Australia, Canada, France, Germany, India, Japan, Brazil, Switzerland, UAE, Sweden). Target sectors: aerospace and defense, automotive, electronics, pharmaceuticals, satellite, oil and gas, mining, finance, government. Malware: PlugX RAT, RedLeaves backdoor, QuasarRAT; extensive use of legitimate tools (certutil, PowerShell, WMI, net.exe, at.exe). Initial access: spear-phishing; credential harvesting. Lateral technique: MSP privileged access reuse; VPN credentials; legitimate remote management tools. Dwell time: months to years in some client environments. Allied attribution: US, UK, Australia, Canada, Japan, New Zealand simultaneous coordinated statement (December 20, 2018). Strategic context: target selection aligned with Made in China 2025 industrial priority sectors. Legal outcome: Zhu Hua and Zhang Shilong charged; no extradition; both believed to remain in China. Defendant status: at large.