Free tools Windows power users keep installed
One-click scans. No signup required.
Public reporting did not settle who was behind the 2018 intrusion at Norwegian software and managed-service provider Visma. Recorded Future and Rapid7 attributed the campaign to APT10; Microsoft and PwC researchers argued that the evidence fit APT31, also known as Zirconium. The disagreement concerned the group attribution—not whether the intrusion happened—and remained unresolved in the contemporary reports.
What happened at Visma?
Recorded Future and Rapid7 said they tracked a campaign from November 2017 through September 2018 that affected at least three organizations: Visma, an international apparel company and a U.S. law firm. Their account described attackers using stolen valid credentials to access remote-access software, including Citrix and LogMeIn, before escalating privileges and using DLL sideloading. CyberScoop’s February 6, 2019 report summarized those findings.
The researchers said the attackers may have targeted Visma as a way to reach its clients’ networks through the service provider, rather than mainly to steal Visma’s own intellectual property. Visma said no client data was compromised. The company also said it chose not to issue a general alert before it had conclusive evidence about who performed the theft.
Why did researchers disagree about APT10?
Recorded Future and Rapid7’s APT10 assessment
Recorded Future and Rapid7 assessed the campaign as APT10 with high confidence. Their case included the presence of Trochilus malware at Visma and a backdoor they associated with APT10. They also described command-and-control communications using RC4 and Salsa20, and UPPERCUT/ANEL malware in the apparel-company and law-firm intrusions. These were elements of their attribution case, not independent proof of the actor’s identity.
#1 Best Overall
The researchers acknowledged a complication: they thought portions of the activity then grouped under APT10 might later be recategorized as another group, but said they lacked enough information at the time to make that distinction. CyberScoop’s February 12, 2019 report documented the competing assessments and that caveat.
Microsoft and PwC’s APT31/Zirconium assessment
Benjamin Koehl, an analyst at Microsoft’s Threat Intelligence Center, said the activity was APT31, which Microsoft called Zirconium. He pointed to command-and-control (C2) domain registrations and subsequent changes that Microsoft associated with Zirconium. CyberScoop reported Koehl’s claim that Zirconium had registered more than 50 domains in the manner he described; that figure was part of his explanation, not a count that independently proves responsibility for the Visma intrusion.
Kris McConkey, then head of cyberthreat detection and response at PwC, also said the reported C2 infrastructure belonged to APT31. He said PwC had not seen APT10 use Trochilus in the manner described and remarked, “None of the stuff that we were tracking as APT10 overlaps with what Recorded Future and Rapid7 have reported.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Did Recorded Future change its mind?
Not in the contemporary reporting. Recorded Future’s Priscilla Moriuchi said APT10 and APT31 showed strong similarities and might be part of the same Chinese state organization. She said the investigation was ongoing and the company would update its report if necessary, adding, “We’re always open to reassessing our judgements if new facts come to light.” That leaves the public record as a live attribution dispute, not a final adjudication.
Quick Recap
Best Value
Rank #4
Rank #3
What can be concluded about the Visma intrusion?
- The incident was attributed to APT10 by Recorded Future and Rapid7, while Microsoft and PwC researchers argued for APT31/Zirconium.
- The competing cases drew on technical indicators, including malware, C2 infrastructure and observed attacker behavior, but the contemporary accounts do not independently resolve which group was responsible.
- The campaign was reported to have affected Visma and two other organizations. The researchers said Visma could have been targeted as a route toward client networks; Visma said client data was not compromised.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

