ATT&CKGroupsmenuPass

menuPass

G0045

Threat group.View on attack.mitre.org

About this group

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.

Techniques used46

Procedure examples46

TechniqueProcedure example
T1003.002
Security Account Manager

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.003
NTDS

menuPass has used Ntdsutil to dump credentials.

T1003.004
LSA Secrets

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1005
Data from Local System

menuPass has collected various files from the compromised computers.

T1016
System Network Configuration Discovery

menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions.

T1018
Remote System Discovery

menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.

T1021.001
Remote Desktop Protocol

menuPass has used RDP connections to move across the victim network.

T1021.004
SSH

menuPass has used Putty Secure Copy Client (PSCP) to transfer data.

T1027.013
Encrypted/Encoded File

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1036
Masquerading

menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files.

T1036.003
Rename Legitimate Utilities

menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.

T1036.005
Match Legitimate Resource Name or Location

menuPass has been seen changing malicious files to appear legitimate.

T1039
Data from Network Shared Drive

menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data.

T1046
Network Service Discovery

menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest.

T1047
Windows Management Instrumentation

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

View all 46 procedure examples

Software25

Show 1 more

Campaigns0

None recorded.

References7

  1. Crowdstrike CrowdCast Oct 2013 Open source
    Crowdstrike. (2013, October 16). CrowdCasts Monthly: You Have an Adversary Problem. Retrieved November 17, 2024.
  2. DOJ APT10 Dec 2018 Open source
    United States District Court Southern District of New York (USDC SDNY) . (2018, December 17). United States of America v. Zhu Hua and Zhang Shilong. Retrieved April 17, 2019.
  3. District Court of NY APT10 Indictment December 2018 Open source
    US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.
  4. FireEye APT10 April 2017 Open source
    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.
  5. FireEye Poison Ivy Open source
    FireEye. (2014). POISON IVY: Assessing Damage and Extracting Intelligence. Retrieved September 19, 2024.
  6. PWC Cloud Hopper April 2017 Open source
    PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.
  7. Palo Alto menuPass Feb 2017 Open source
    Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.