EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/apt10-cloud-hopper-2016
257/430

File EL-0174CriticalResolvedEspionage Operation / Supply Chain Compromise

Operation Cloud Hopper

Also filed as APT10 Managed Service Provider Attack · Stone Panda Operation

Operation Cloud Hopper was a sophisticated, multi-stage espionage campaign targeting Managed Service Providers (MSPs) globally. The attackers leveraged the trusted relationships and inherent trust within the MSP supply chain to gain access to high-value client networks. This operation demonstrated a highly coordinated effort to exfiltrate sensitive government and corporate intelligence from multiple international targets.

  • #apt10
  • #cloud-hopper
  • #managed-service-provider
  • #china-mss
  • #supply-chain-attack
  • #espionage
Notoriety8/10
Event
1 Jan 2016
Disclosed
1 Mar 2016
Target
Managed Service Providers (MSPs)
Actor
APT10
Scale
Unknown (estimated to be massive, involving years of data)
Status
Resolved

01Summary

The campaign, attributed to APT10 (also known as Stone Panda), focused on compromising the infrastructure of Managed Service Providers. By infiltrating these third-party vendors, the threat actors could bypass traditional perimeter defenses and gain lateral access to the networks of their clients, who often included government agencies and critical infrastructure operators. The attackers utilized custom malware and sophisticated techniques to maintain persistence and exfiltrate data over an extended period. The scope was vast, affecting dozens of MSPs and granting access to client data across more than a dozen countries, making it a prime example of supply chain risk.

02Background

The increasing reliance of critical infrastructure and government agencies on third-party Managed Service Providers created a lucrative and vulnerable attack vector. APT10 capitalized on this systemic weakness, recognizing that compromising a single, trusted vendor could provide access to numerous high-value targets simultaneously. This shift in focus marked a maturation in state-sponsored cyber espionage tactics.

03Key revelations

  1. 01The successful exploitation of the inherent trust model within the MSP industry.
  2. 02The ability to compromise multiple, unrelated high-value targets (governments, defense contractors) from a single vendor point.
  3. 03The use of highly customized, multi-stage malware designed for long-term, undetected espionage.

04Technical analysis

The attack chain typically involved initial compromise of the MSP's internal systems, often through spear-phishing or exploiting unpatched vulnerabilities. Once inside, the threat actors established multiple backdoors and used custom malware to map the network. They then moved laterally through the MSP's privileged access points to reach the client networks, bypassing client-side security measures that might have otherwise detected the intrusion.

Attack vector
Compromise of the Managed Service Provider's internal network (e.g., phishing, exploiting vendor vulnerabilities).
Attack method
Supply Chain Compromise and Lateral Movement
Initial access
Compromise of the MSP's perimeter or internal systems.
Lateral movement
Using privileged access credentials and network trust relationships provided by the MSP.
Persistence
Installation of multiple backdoors and persistent remote access tools.
Exfiltration
Encrypted channels over standard network protocols (e.g., DNS tunneling or HTTPS).
Tool / malware
Custom backdoors and malware (specific names often classified or proprietary to the report).
Malware type
Backdoor/Stealer

MITRE ATT&CK techniques

  • T1566.001
  • T1078
  • T1021

05Threat actor

APT10, also known as Stone Panda, is widely attributed to the Chinese Ministry of State Security (MSS). The group specializes in highly targeted, long-term espionage campaigns, focusing on compromising critical infrastructure and government entities globally. Their methodology emphasizes supply chain exploitation to maximize access and minimize detection risk.

Aliases

  • Stone Panda
  • China MSS

APT designations

  • APT10

MITRE groups

  • T1190
  • T1566.001
  • T1078

Attribution sources

  • Mandiant
  • FireEye
  • Cybersecurity Industry Reports

06Victims and impact

Additional victims

  • Client Networks (various governments and corporations)

Countries affected

  • United States
  • United Kingdom
  • Australia
  • Canada
  • European Union

07Data exposed

Data types

  • Credentials
  • Government Communications
  • Corporate Intellectual Property
  • Sensitive PII

Notable documents

  • Client network credentials
  • Government communications intercepts
  • Intellectual property blueprints

08Financial damage

Damage estimate is based on the loss of intellectual property and operational disruption, not a direct ransom payment.

09Timeline

  1. 2015-12-01Initial compromise of MSP infrastructure begins.
  2. 2016-03-01Incident publicly disclosed by security firms.
  3. 2016-06-01Estimated end of the primary operational window.

10Reaction and fallout

Public reaction

The incident prompted a global reassessment of third-party risk management, forcing governments and corporations to scrutinize their vendor relationships. It highlighted the systemic vulnerability inherent in the modern, interconnected digital economy.

Political impact

It increased international scrutiny on China's cyber espionage capabilities, particularly targeting Western government and defense sectors. It contributed to the hardening of national cyber defense policies.

Geopolitical consequences

The attack reinforced the concept of 'cyber sovereignty,' leading to increased bilateral agreements and export controls related to critical technology infrastructure.

11Legal

No specific criminal charges were publicly filed against the perpetrators, but the incident contributed to increased legal focus on supply chain security and data residency laws.

Civil lawsuits

  • Increased litigation risk for MSPs failing to implement robust security controls.

12Aftermath

Policy changes

  • Mandatory third-party risk assessments (TPRA) for critical infrastructure.
  • Increased adoption of Zero Trust Architecture (ZTA) models.

Regulatory changes

  • Stricter data localization and cross-border data transfer regulations (e.g., GDPR enforcement).

Security improvements

  • Implementation of network segmentation between client environments.
  • Mandatory multi-factor authentication (MFA) for all vendor access points.

13Significance and legacy

Significance

Operation Cloud Hopper is a landmark case study in supply chain cyberattacks. It demonstrated that the weakest link in a highly secure system is often the trusted third party. The attack forced the cybersecurity industry to move beyond perimeter defense and adopt a holistic, risk-based approach to vendor management.

Legacy

The incident permanently elevated the risk of the Managed Service Provider (MSP) model in the eyes of security professionals. It accelerated the adoption of Zero Trust principles and led to the creation of specialized third-party risk management frameworks globally.

14Disclosure and media

Authentication
Technical analysis of malware and network traffic patterns.

Media partners

  • Mandiant
  • FireEye

Publishing organisations

  • Mandiant
  • FireEye

15Field notes

  1. 01The attack was notable for its breadth, affecting multiple sectors (government, defense, finance) rather than focusing on a single industry.
  2. 02The use of MSPs allowed the attackers to operate under a veil of trust, making detection significantly harder for client-side security teams.

16Resolution

The threat actors were eventually identified and attributed, leading to increased defensive measures and industry best practices regarding vendor vetting and network isolation.

17Sources

Official documents

  • Mandiant Threat Report (2016)

References

  1. [1]Mandiant Threat Report: APT10
  2. [2]FireEye Research Findings
Fact sheetEL-0174

Dates

Event
1 Jan 2016
Started
1 Dec 2015
Ended
1 Jun 2016
Discovered
1 Mar 2016
Disclosed
1 Mar 2016
Ongoing
No

Target

Organisation
Managed Service Providers (MSPs)
Type
Technology Company
Sector
Government/Defense/Critical Infrastructure
Country
Global
Gov. level
Federal

Actor

Name
APT10
Type
Nation-State Actor
Nationality
Chinese
Nation-state
China
Affiliation
Ministry of State Security (MSS)
Motivation
Geopolitical intelligence gathering and industrial espionage targeting foreign governments and critical infrastructure.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Unknown (estimated to be massive, involving years of data)
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.