Adversary-emulation profile for APT10 (G0045 / Stone Panda / menuPass / POTASSIUM / Red Apollo / CVNX), China's MSS Tianjin State Security Bureau cyber-espionage actor.
32
27%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt10-stone-panda/SKILL.mdAPT10 (MITRE ATT&CK G0045) is a long-running Chinese cyber-espionage group active since at least 2006, attributed to China's Ministry of State Security (MSS) Tianjin State Security Bureau. Individual members have been identified as working for the Huaying Haitai Science and Technology Development Company. APT10 is best known for Operation Cloud Hopper — the systematic, large-scale compromise of managed IT service providers (MSPs) to pivot into hundreds of downstream client organizations worldwide — a paradigm-defining supply-chain attack. The group's toolkit spans custom implants (PlugX, RedLeaves, ChChes, UPPERCUT/ANEL, SodaMaster, Ecipekac), public frameworks (QuasarRAT, Cobalt Strike, Mimikatz, PsExec), and heavy reliance on DLL side-loading for evasion. Targeting is broad: healthcare, defense, aerospace, government, telecom, maritime, finance, and biotechnology, with a persistent emphasis on Japanese organizations and Western MSPs.
cmd.exe, modified wmiexec.vbs scripts, and macro-triggered command execution.wmiexec.vbs to execute commands on remote systems via WMI.atexec.py to execute commands on remote systems via the Task Scheduler.GetModuleFileName, CreateFile, ReadFile, and other Windows APIs directly.iexplore.exe to load RedLeaves implant.certutil and moved it to evade detection; changed malicious file extensions and names to match legitimate software.wevtutil to remove PowerShell execution logs.certutil -decode to decode base64-encoded payloads in macros and during UPPERCUT deployment.InstallUtil.exe to execute malicious .NET assemblies, bypassing application whitelisting.secretsdump.py and pwdump6 to dump SAM database credentials.ntdsutil to dump the Active Directory database.wmiexec.vbs and secretsdump.py to extract LSA secrets.csvde.exe and AdFind to export Active Directory data; net user /domain enumeration.tcping.exe and port-scanning tools to probe open services on target systems.net view /domain through PlugX; used Ping for host discovery.net use for connectivity checks.net use for remote execution and file transfer over admin shares.cmd, and esentutl to move tools across compromised systems.net use and used Robocopy to transfer data from shared drives.csvde for automated Active Directory data collection.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| PlugX | S0013 | Modular RAT (HTTP/DNS C2, DLL side-loading, keylogging) | Custom |
| RedLeaves | S0153 | Windows backdoor (HTTP C2, DLL side-loading) | Custom |
| ChChes | S0144 | Lightweight backdoor (HTTP C2, cookie-based comms) | Custom |
| UPPERCUT / ANEL | S0275 | Backdoor (HTTP C2, UAC bypass, DLL side-loading) | Custom |
| SNUGRIDE | S0159 | Windows backdoor (HTTP C2) | Custom |
| Poison Ivy | S0012 | RAT (keylogging, screen capture, service persistence) | Custom (shared) |
| EvilGrab | S0152 | Audio/video/keylog capture backdoor | Custom |
| SodaMaster | S0627 | Fileless backdoor (anti-sandbox, RSA+AES encrypted C2) | Custom |
| Ecipekac | S0624 | Multi-layered loader (4-layer encryption, code-signing abuse) | Custom |
| P8RAT | S0626 | Fileless backdoor (anti-sandbox, junk-data C2 obfuscation) | Custom |
| FYAnti | S0628 | .NET downloader/loader (packed, used in A41APT) | Custom |
| HUI Loader | S1097 | DLL side-loading loader (defense evasion, deobfuscation) | Custom |
| QuasarRAT | S0262 | Open-source .NET RAT (keylogging, screen capture, file manager) | Public |
| Cobalt Strike | S0154 | Post-exploitation framework (Beacon implant) | Public (commercial) |
| Mimikatz | S0002 | Credential dumping (LSASS, SAM, DCSync, pass-the-hash) | Public |
| Impacket | S0357 | Python network toolkit (secretsdump, wmiexec, atexec) | Public |
| PowerSploit | S0194 | PowerShell post-exploitation (injection, credential access) | Public |
| PsExec | S0029 | Remote execution via SMB/service | Public (Sysinternals) |
| pwdump | S0006 | SAM credential dumping | Public |
| AdFind | S0552 | Active Directory enumeration | Public |
| certutil | S0160 | LOLBin (decode, download, certificate manipulation) | Built-in |
| Net | S0039 | LOLBin (account/share/service enumeration) | Built-in |
| cmd | S0106 | LOLBin (command execution, file operations) | Built-in |
| Wevtutil | S0645 | LOLBin (event log clearing) | Built-in |
| esentutl | S0404 | LOLBin (data copy, NTFS attribute access) | Built-in |
| Ping | S0097 | LOLBin (host discovery) | Built-in |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never run destructive actions outside an explicitly sanctioned, isolated lab.
Map APT10's signature plays to Decepticon's own capabilities:
secretsdump.py for LSA secrets and NTDS extraction via ntdsutil. Deploy keyloggers to capture credentials in real time. In Cloud Hopper emulation, focus on harvesting MSP admin credentials that grant access to client tenants.iexplore.exe or another benign process. Use the evasion skill to spawn a suspended legitimate process, hollow its memory, and inject implant code — a key detection-engineering exercise.net view /domain and IP range scanning for network mapping. Search for high-value document folders (HR, finance, R&D) to emulate APT10's targeted collection behavior.certutil for payload decoding; use InstallUtil.exe for .NET assembly execution; clear PowerShell logs with wevtutil. These LOLBin abuse patterns should be emulated for EDR/SIEM validation.ntdsutil execution, reg save of SAM/SYSTEM/SECURITY hives, and secretsdump-style network activity; restrict debug privileges.cmd.exe, PowerShell, certutil, or InstallUtil.iexplore.exe or other browser processes running without user interaction or from unusual parent processes.certutil -decode and certutil -urlcache usage; monitor InstallUtil.exe executing assemblies from non-standard paths; detect wevtutil cl for log clearing.net use mapping of admin shares and Robocopy execution.*.hopto.org, *.no-ip.org); inspect HTTPS traffic to newly registered or low-reputation domains; monitor for non-standard port usage by common processes.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.