> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
RED APOLLO (APT10)
/actor/red-apollo-apt10/ · 0 intel reports
Red Apollo, designated APT10 by researchers, is a Chinese state-sponsored threat actor attributed to the Ministry of State Security (MSS) Tianjin Bureau and assessed to be one of China's most prolific and damaging intellectual property theft operations. Active since at least 2009, the group's operations have targeted a vast range of industries across dozens of countries in sustained campaigns designed to systematically transfer cutting-edge technology and business intelligence to Chinese state interests.
APT10's most significant campaign, dubbed "Operation Cloud Hopper" by PricewaterhouseCoopers and BAE Systems, targeted Managed Service Providers (MSPs) , IT companies that manage the computer networks of multiple corporate clients simultaneously. By compromising MSP infrastructure, APT10 gained simultaneous access to the networks of dozens or hundreds of MSP client organisations across multiple countries with a single intrusion, dramatically multiplying the efficiency of their espionage operations. The campaign targeted MSPs across Japan, India, the UK, US, Australia, Canada, Brazil, France, and Switzerland.
Sectors targeted by APT10 include aerospace, satellite technology, pharmaceutical, healthcare, automotive, manufacturing, oil and gas, mining, defence, and financial services , representing an extraordinarily broad intellectual property theft mandate aligned with Chinese national industrial policy objectives. The breadth of targeting reflects the scope of China's "Made in China 2025" industrial strategy and the use of cyber espionage to accelerate domestic technological development.
In December 2018, the US Department of Justice indicted two MSS officers linked to APT10 operations, and the UK, EU, Australia, Japan, and other allies simultaneously issued coordinated attribution statements condemning the group's operations , one of the most significant multilateral cyber attribution events in history, reflecting the global scale of APT10's theft campaigns.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Red Apollo (APT10) requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.