<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Red_Apollo</id>
	<title>Red Apollo - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Red_Apollo"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Red_Apollo&amp;action=history"/>
	<updated>2026-08-02T04:42:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Red_Apollo&amp;diff=430216&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Red_Apollo&amp;diff=430216&amp;oldid=prev"/>
		<updated>2023-09-25T18:45:26Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{short description|Chinese cyberespionage group}}&lt;br /&gt;
{{about|the threat actor|the butterfly|Parnassius epaphus|the element|Potassium}}&lt;br /&gt;
{{Infobox organization&lt;br /&gt;
| name = Red Apollo&lt;br /&gt;
| named_after = &lt;br /&gt;
| image = &lt;br /&gt;
| alt = &lt;br /&gt;
| formation = {{circa}} 2003–2005{{ref|a}}&lt;br /&gt;
| type = [[Advanced persistent threat]]&lt;br /&gt;
| purpose = [[Cyberespionage]], [[cyberwarfare]]&lt;br /&gt;
| motto = &lt;br /&gt;
| headquarters = &lt;br /&gt;
| region = [[China]]&lt;br /&gt;
| methods = [[Zero-day (computing)|Zero-day]]s, [[spearphishing|Phishing]], [[backdoor (computing)]], [[Remote Access Trojan|RAT]], [[Keylogging]]&lt;br /&gt;
| membership = &lt;br /&gt;
| leader_name = &lt;br /&gt;
| language = [[Chinese language|Chinese]]&lt;br /&gt;
| parent_organization = [[Tianjin State Security Bureau]] of the [[Ministry of State Security (China)|Ministry of State Security]]&lt;br /&gt;
| affiliations = &lt;br /&gt;
| formerly = APT10&amp;lt;br/&amp;gt;Stone Panda&amp;lt;br/&amp;gt;MenuPass&amp;lt;br/&amp;gt;RedLeaves&amp;lt;br/&amp;gt;CVNX&amp;lt;br/&amp;gt;POTASSIUM&amp;lt;br/&amp;gt;&lt;br /&gt;
| website = &lt;br /&gt;
| remarks = &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Red Apollo&amp;#039;&amp;#039;&amp;#039; (also known as &amp;#039;&amp;#039;&amp;#039;APT 10&amp;#039;&amp;#039;&amp;#039; (by [[Mandiant]]), &amp;#039;&amp;#039;&amp;#039;MenuPass&amp;#039;&amp;#039;&amp;#039; (by [[Fireeye]]), &amp;#039;&amp;#039;&amp;#039;Stone Panda&amp;#039;&amp;#039;&amp;#039; (by [[Crowdstrike]]), and &amp;#039;&amp;#039;&amp;#039;POTASSIUM&amp;#039;&amp;#039;&amp;#039; (by [[Microsoft]]))&amp;lt;ref&amp;gt;{{Cite web|title=APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat|url=https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html|access-date=2021-03-07|website=FireEye|language=en}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web|last=Kozy|first=Adam|date=2018-08-30|title=Two Birds, One STONE PANDA|url=https://www.crowdstrike.com/blog/two-birds-one-stone-panda/|access-date=2021-03-07|language=en-US}}&amp;lt;/ref&amp;gt; is a [[People&amp;#039;s Republic of China|Chinese]] state-sponsored [[cyberespionage]] group which has operated since 2006. In a 2018 indictment, the [[United States Department of Justice]] attributed the group to the [[Tianjin State Security Bureau]] of the [[Ministry of State Security (China)|Ministry of State Security]].&amp;lt;ref&amp;gt;{{Cite web|date=2018-12-20|title=Two Chinese Hackers Associated With the Ministry of State Security Charged with Global Computer Intrusion Campaigns Targeting Intellectual Property and Confidential Business Information|url=https://www.justice.gov/opa/pr/two-chinese-hackers-associated-ministry-state-security-charged-global-computer-intrusion|url-status=live|access-date=2021-03-07|website=[[United States Department of Justice]]|language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The team was designated an Advanced Persistent Threat by Fireeye, who reported that they target aerospace, engineering, and telecom firms and any government that they believe is a rival of [[China]].&lt;br /&gt;
&lt;br /&gt;
Fireeye stated that they could be targeting intellectual property from educational institutions such as a Japanese university and is likely to expand operations into the education sector in the jurisdictions of nations that are allied with the [[United States]].&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;{{Cite web|date=April 6, 2017|title=APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat « APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat|url=https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html|url-status=live|website=FireEye}}&amp;lt;/ref&amp;gt; Fireeye claimed that they were tracked since 2009, however because of the low-threat nature they had posed, they were not a priority. Fireeye now describes the group as &amp;quot;a threat to organizations worldwide.&amp;quot;&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Tactics==&lt;br /&gt;
&lt;br /&gt;
The group directly targets managed information technology service providers (MSPs) using [[Remote Access Trojan|RAT]]. The general role of an MSP is to help manage a company&amp;#039;s computer network. MSPs were often compromised by Poison Ivy, FakeMicrosoft, PlugX, ArtIEF, [[Graftor]], and ChChes, through the use of [[spear-phishing]] emails.&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;{{Cite web|date=April 10, 2017|title=Operation Cloud Hopper: What You Need to Know - Security News - Trend Micro USA|url=https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-cloud-hopper-what-you-need-to-know|url-status=live|website=trendmicro.com}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==History==&lt;br /&gt;
&lt;br /&gt;
=== 2014 to 2017: Operation Cloud Hopper ===&lt;br /&gt;
Operation Cloud Hopper was an extensive attack and theft of information in 2017 directed at MSPs in the United Kingdom (U.K.), United States (U.S.), Japan, Canada, Brazil, France, Switzerland, Norway, Finland, Sweden, South Africa, India, Thailand, South Korea and Australia. The group used MSP&amp;#039;s as intermediaries to acquire assets and trade secrets from MSP-client engineering, industrial manufacturing, retail, energy, pharmaceuticals, telecommunications, and government agencies.&lt;br /&gt;
&lt;br /&gt;
Operation Cloud Hopper used over 70 variants of backdoors, [[malware]] and [[Trojan horse (computing)|trojans]]. These were delivered through spear-phishing emails. The attacks scheduled tasks or leveraged services/utilities to persist in [[Microsoft Windows]] systems even if the computer system was rebooted. It installed malware and hacking tools to access systems and steal data.&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 2016 US Navy personnel data ===&lt;br /&gt;
Hackers accessed records relating to 130,000 [[US Navy]] personnel (out of 330,000).&amp;lt;ref&amp;gt;{{Cite web|url=https://www.technologyreview.com/f/612655/chinese-hackers-allegedly-stole-data-of-more-than-100000-us-navy-personnel/|title=Chinese hackers allegedly stole data of more than 100,000 US Navy personnel|website=MIT Technology Review}}&amp;lt;/ref&amp;gt; Under these actions the Navy decided to coordinate with [[Hewlett Packard Enterprise Services]], despite warnings being given prior to the breach.&amp;lt;ref&amp;gt;{{Cite web|url=https://www.bankinfosecurity.com/us-navy-sailor-data-accessed-by-unknown-individuals-a-9560|title=US Navy Sailor Data &amp;#039;Accessed by Unknown Individuals&amp;#039;|website=bankinfosecurity.com}}&amp;lt;/ref&amp;gt; All affected sailors were required to be notified.&lt;br /&gt;
&lt;br /&gt;
=== 2018 Indictments ===&lt;br /&gt;
A 2018 Indictment showed evidence that CVNX was not the name of the group, but was the alias of one of two hackers. Both used four aliases each to make it appear as if more than five hackers had attacked.&lt;br /&gt;
&lt;br /&gt;
=== Post-Indictment activities ===&lt;br /&gt;
In April 2019 APT10 targeted government and private organizations in the [[Philippines]].&amp;lt;ref&amp;gt;{{cite news |last1=Manantan |first1=Mark |title=The Cyber Dimension of the South China Sea Clashes |url=https://magazine.thediplomat.com/#/issues/-LnBlVlS_1DsiVyAVtMQ/read |access-date=5 September 2019 |agency=The Diplomat |issue=58 |publisher=The Diplomat |date=September 2019}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In 2020 Symantec implicated Red Apollo in a series of attacks on targets in Japan.&amp;lt;ref&amp;gt;{{cite web |last1=Lyngaas |first1=Sean |title=Symantec implicates APT10 in sweeping hacking campaign against Japanese firms |url=https://www.cyberscoop.com/apt10-china-japan-intellectual-property-symantec/ |website=www.cyberscoop.com |date=17 November 2020 |publisher=Cyberscoop |access-date=19 November 2020}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In March 2021, they targeted [[Bharat Biotech]] and the [[Serum Institute of India|Serum Institute of India (SII)]], the world&amp;#039;s largest vaccine maker&amp;#039;s intellectual property for [[data theft|exfiltration]].&amp;lt;ref&amp;gt;{{Cite news|last=N. Das|first=Krishna|date=1 March 2021|title=Chinese hacking group Red Apollo (APT10) had identified gaps and vulnerabilities in the IT infrastructure and supply chain software of Bharat Biotech and the Serum Institute of India (SII), the world&amp;#039;s largest vaccine maker|work=[[Reuters]]|url=https://www.reuters.com/article/health-coronavirus-india-china-idUSKCN2AT21O|url-status=live|access-date=1 March 2021}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
*[[China–United States relations]]&lt;br /&gt;
*[[Cyberwarfare by China]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
{{MSS}}&lt;br /&gt;
[[Category:Cyberespionage units of the Ministry of State Security (China)]]&lt;br /&gt;
[[Category:Chinese advanced persistent threat groups]]&lt;br /&gt;
[[Category:Cyberwarfare by China]]&lt;br /&gt;
[[Category:Hacker groups]]&lt;br /&gt;
[[Category:Hacking in the 2000s]]&lt;br /&gt;
[[Category:Hacking in the 2010s]]&lt;br /&gt;
[[Category:Information technology in China]]&lt;br /&gt;
[[Category:Military units and formations established in the 2000s]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>