LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0045: menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.CitationDOJ APT10 Dec 2018CitationDistrict Court of NY APT10 Indictment December 2018

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.CitationPalo Alto menuPass Feb 2017CitationCrowdstrike CrowdCast Oct 2013CitationFireEye Poison IvyCitationPWC Cloud Hopper April 2017CitationFireEye APT10 April 2017CitationDOJ APT10 Dec 2018CitationDistrict Court of NY APT10 Indictment December 2018

EnterpriseG0045GroupObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

menuPass is an ATT&CK group with a long reported history, broad sector targeting, and documented interest in Japanese organizations and managed IT service providers. The practical issue for leaders is third-party and identity risk: the related tooling includes credential dumpers, remote access tools, command-line utilities, Active Directory query tooling, and remote execution utilities, which are the kinds of capabilities that can turn one compromised endpoint or provider relationship into wider enterprise access.

Executive priority

Prioritize menuPass as a planning reference for resilience against targeted intrusion, especially if the organization operates in healthcare, defense, aerospace, finance, maritime, biotechnology, energy, government, manufacturing, mining, higher education, Japan-linked operations, or MSP-dependent environments named in the ATT&CK description. Executive questions should focus on whether privileged identity controls, MSP access governance, Windows endpoint visibility, and incident response playbooks can withstand credential theft, remote access malware, and legitimate admin-tool abuse. This object is also useful for audit and compliance evidence because it maps defensive investment to a documented adversary profile rather than generic malware risk.

Technical view

ATT&CK does not provide a detection section, platforms, or tactics for the group object itself, so SOC validation should be relationship-driven. The associated software set is heavily Windows-oriented and includes Mimikatz, pwdump, PoisonIvy, PlugX, PsExec, Net, cmd, ChChes, EvilGrab, RedLeaves, SNUGRIDE, certutil, PowerSploit, QuasarRAT, UPPERCUT, esentutl, AdFind, Ecipekac, P8RAT, SodaMaster, and FYAnti, plus cross-platform tooling such as Cobalt Strike and Impacket. Detection engineering should validate coverage for credential dumping, suspicious command-line activity, Active Directory enumeration, remote service execution, fileless or loader-style malware behavior, and outbound remote access/backdoor communications without assuming any single tool name will appear in telemetry.

Likely telemetry

  • Windows endpoint process creation and command-line logs for cmd, Net, PsExec, certutil, esentutl, PowerShell/PowerSploit-like activity, and AdFind-like directory queries
  • Authentication, privilege use, and lateral movement evidence from Windows security logs, domain controller logs, and remote administration events
  • Endpoint detections or memory/behavioral telemetry associated with credential dumping tools such as Mimikatz and pwdump
  • Network, DNS, proxy, and firewall logs showing unusual outbound connections or remote access tool/backdoor communications associated with RAT-style software
  • Email and endpoint telemetry around malicious Microsoft Office document execution, where applicable to EvilGrab-related spearphishing context

Detection direction

  • Do not rely only on static malware names; several related tools are legitimate utilities or public frameworks also used by administrators and testers.
  • Baseline administrative use of PsExec, Net, cmd, certutil, esentutl, AdFind, Impacket, and Cobalt Strike-like tooling so alerts can separate expected operations from unusual hosts, users, times, parent processes, or command arguments.
  • Correlate credential dumping indicators with subsequent authentication anomalies, remote execution, directory enumeration, and outbound communications to reduce false positives and improve incident confidence.
  • Validate domain controller and endpoint visibility for Active Directory reconnaissance because AdFind and native Windows utilities can leave limited evidence if command-line logging is weak.
  • Review detection gaps for fileless malware and loader behavior reflected by P8RAT, SodaMaster, Ecipekac, and FYAnti relationships; pure file-hash controls are unlikely to be sufficient.

Mitigation priorities

  • First strengthen identity controls: reduce standing privilege, enforce strong authentication for administrative and remote access paths, and monitor privileged credential use.
  • Harden Windows endpoints and servers against credential theft by limiting credential exposure, restricting local administrator use, and ensuring endpoint telemetry is retained for investigation.
  • Govern dual-use administrative tools with allowlisting, approved-use baselines, and alerting for unexpected execution of PsExec, Net, cmd, certutil, esentutl, AdFind, Impacket, and PowerShell-based frameworks.
  • Review MSP and third-party access paths, including least privilege, logging, segmentation, and incident notification expectations.
  • Improve egress monitoring and network segmentation to limit the value of RATs, backdoors, and post-exploitation frameworks if an endpoint is compromised.
Additional notes and limits

The strongest defensive signal in this object comes from the combination of official targeting history and the software relationships. The group is associated in ATT&CK with multiple aliases, including APT10, Cicada, POTASSIUM, Stone Panda, Red Apollo, CVNX, HOGFISH, and BRONZE RIVERSIDE. ATT&CK states members are known to have acted in association with the Chinese MSS Tianjin State Security Bureau and Huaying Haitai Science and Technology Development Company; this take does not extend that statement beyond the supplied source text.

ATT&CK provides no official detection guidance, tactics, or platforms on the group object itself. Platform implications are inferred only from related software descriptions, many of which are Windows-focused. Local relevance depends on the organization’s sector, geography, MSP exposure, identity architecture, and actual telemetry coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.CitationDOJ APT10 Dec 2018CitationDistrict Court of NY APT10 Indictment December 2018

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.CitationPalo Alto menuPass Feb 2017CitationCrowdstrike CrowdCast Oct 2013CitationFireEye Poison IvyCitationPWC Cloud Hopper April 2017CitationFireEye APT10 April 2017CitationDOJ APT10 Dec 2018CitationDistrict Court of NY APT10 Indictment December 2018

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
6295379e6c9b138f...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.