APT10 Cloud Hopper: How China Compromised 45 MSPs to Reach Hundreds of Their Clients Simultaneously
Between 2016 and 2018, Chinese state hackers ran the most systematically ambitious espionage operation against Western commercial targets that had been publicly documented to that point. APT10, a group attributed to China's Ministry of State Security, compromised at least 45 managed service providers (MSPs) across 12 countries. The MSPs were not the targets - they were the means of access. Through the compromised MSPs, APT10 reached the intellectual property, business strategies, and confidential information of hundreds of client organizations across aerospace, defense, automotive, electronics, pharmaceuticals, manufacturing, satellites, and financial services. The operation was called Cloud Hopper.
The MSP targeting strategy was the architectural innovation that made Cloud Hopper distinct. Managed service providers maintain privileged, persistent access to their clients' networks by design - that is what clients pay for. By compromising the MSP, APT10 obtained that pre-built, trusted access to every client the MSP served. One intrusion created a springboard to hundreds of targets. The trust relationship that makes MSPs valuable to their clients made MSPs dangerous as a lateral access point when compromised.
The Attack Chain
APT10's initial access methodology in Cloud Hopper relied heavily on spear-phishing. Targeted employees at MSPs received emails with malicious attachments or links; the resulting malware established a foothold in the MSP's own environment. From there, APT10 used the MSP's legitimate administrative tools and credentials to pivot into client environments. Because the access looked like normal MSP management activity - using the MSP's own tools, from the MSP's own IP space, with the MSP's own credentials - it was extremely difficult for client organizations to distinguish malicious activity from routine MSP administration.
Once inside client environments, APT10 conducted targeted exfiltration focused on intellectual property: technical designs, manufacturing specifications, business plans, and contract information. The group demonstrated significant patience - maintaining access over months or years rather than conducting rapid mass exfiltration. In some cases, APT10 maintained presence inside client networks for years before detection.
Scale and Attribution
US and UK joint indictments in December 2018 charged two Chinese nationals, Zhu Hua and Zhang Shilong, as members of APT10 operating under the name Huaying Haitian Science and Technology Co., Ltd. - a front company with ties to the Tianjin Bureau of the MSS. The indictment listed 45 MSPs compromised across 12 countries, with victim industries spanning the full breadth of China's strategic industrial priorities as laid out in the Made in China 2025 plan.
The US, UK, Australia, Canada, Japan, and New Zealand issued coordinated attribution statements simultaneously - the first major multilateral attribution of a Chinese cyber espionage campaign. This coordinated approach reflected lessons learned from years of single-country attributions that China had been able to deflect diplomatically; presenting a unified allied front made dismissal harder and signaled that multiple intelligence services had independently reached the same conclusions.
Made in China 2025 and Strategic Context
Chinese industrial policy context is essential to understanding Cloud Hopper's target selection. China's Made in China 2025 plan, announced in 2015, identified ten strategic industries for Chinese development and global competitiveness: advanced information technology, automated machine tools and robotics, aerospace and aeronautical equipment, maritime engineering and shipping, advanced rail equipment, energy-saving vehicles and electric vehicles, power equipment, agricultural equipment, new materials, and biopharmaceuticals. The APT10 victim list mapped almost exactly onto these sectors. The espionage was not opportunistic; it was targeted collection against the specific commercial and technological domains China's government had publicly identified as strategic priorities.
This pattern of state-directed IP theft aligned with national industrial strategy - using espionage to accelerate domestic industrial capability in targeted sectors - had been documented since the Mandiant APT1 report in 2013 but Cloud Hopper demonstrated its continued scale and sophistication five years after APT1 was publicly exposed. The 2018 indictments were partly designed to impose reputational and economic costs on this strategy by making the intelligence collection-industrial policy connection explicit and public.