menuPass
Also tracked as Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company. menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.
- Known attack methods
- 46
- First seen
- 2006
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques
Resource Development
9 techniques · 2 used
Initial Access
11 techniques · 3 used
Execution
20 techniques · 5 used
Persistence
22 techniques
Privilege Escalation
13 techniques
Stealth
30 techniques · 8 used
Defense Impairment
18 techniques · 1 used
Credential Access
17 techniques · 1 used
Discovery
34 techniques · 6 used
Lateral Movement
9 techniques · 2 used
Collection
17 techniques · 6 used
Command and Control
18 techniques · 3 used
Exfiltration
9 techniques
Impact
15 techniques
Resource development2
Initial access3
Execution6
Stealth11
- T1027.013Encrypted/Encoded File
- T1036Masquerading
- T1036.003Rename Legitimate Utilities
- T1036.005Match Legitimate Resource Name or Location
- T1055.012Process Hollowing
- T1070.003Clear Command History
- T1070.004File Deletion
- T1078Valid Accounts
- T1140Deobfuscate/Decode Files or Information
- T1218.004InstallUtil
- T1574.001DLL
Defense impairment1
Credential access3
Discovery6
Collection8
Command and control3
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.