Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The December 2018 U.S. indictments of Zhu Hua and Zhang Shilong described an alleged APT10 campaign that compromised managed service providers (MSPs) and used their trusted access to reach client networks. The charges are allegations, not convictions. Separately, the United Kingdom’s intelligence assessment attributed the activity known as Operation Cloud Hopper to APT10 and judged China’s Ministry of State Security (MSS) responsible.

The important security lesson is structural: compromising one provider can expose many customers at once when administrative credentials, remote-management tools and network trust are shared.

What happened in December 2018?

On 20 December 2018, the U.S. Department of Justice (DOJ) announced an unsealed indictment against Chinese nationals Zhu Hua and Zhang Shilong. DOJ said they were members of APT10, worked for the Tianjin-based company Huaying Haitai and acted in association with the MSS’s Tianjin State Security Bureau. The defendants were charged with conspiracy to commit computer intrusions, conspiracy to commit wire fraud and aggravated identity theft. The DOJ announcement describes accusations in an indictment; it does not establish guilt or a conviction. Read the DOJ announcement.

DOJ divided the alleged activity into two broad campaigns. The earlier Technology Theft Campaign involved direct targeting of technology companies and U.S. government agencies. The later MSP Theft Campaign allegedly used providers as a stepping stone into their customers’ environments. Contemporary coverage described the indictments as evidence that MSP targeting had expanded in reach, but that characterization should not be confused with a court finding.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did the alleged MSP attack work?

An MSP operates systems or security functions for other organizations, so its technicians and tools may have privileged, remote access to many customer environments. DOJ’s account describes a sequence designed to turn that trust relationship into a collection and exfiltration channel.

1. Establish a foothold at the provider

The indictment alleged that malware on MSP computers enabled remote monitoring and the theft of credentials. A compromised workstation or server could therefore provide both visibility and a route to administrative accounts.

2. Steal and reuse administrator credentials

According to DOJ, the actors used stolen administrative credentials to move through the provider’s systems and into client networks. The danger is not limited to a single infected machine: a credential that is valid across remote-management or support infrastructure can unlock multiple customers.

3. Move laterally through trusted connections

The alleged operators searched the MSP environment and connected customer systems, using existing access paths rather than attacking every client independently. This is why provider compromise can create downstream exposure even when a customer’s perimeter controls have not been directly breached.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Identify and stage valuable data

DOJ alleged that the actors located target information, packaged it into encrypted archives and moved client data among compromised MSP or customer computers. Staging data internally can help an intruder organize a large collection and reduce the need for repeated direct access to the original files.

5. Exfiltrate the collection

The final alleged step was removal of the staged archives from the compromised environment. DOJ said companies affected over the course of the MSP Theft Campaign were located in at least 12 countries. This is the indictment’s description of the operation, not independent validation of every alleged action.

What was Operation Cloud Hopper?

“Operation Cloud Hopper” is the name used in the April 2017 report by PwC UK and BAE Systems for activity in which attackers targeted MSPs and used them to reach customers. The report said the firms had assisted victims since late 2016, assessed that multiple MSPs were almost certainly targeted from 2016 onward and considered targeting likely as early as 2014. See the PwC and BAE Systems report.

The name is therefore a campaign label used by investigators and analysts, not the title of a criminal case. The DOJ indictment used “MSP Theft Campaign” and presented its own allegations. The two accounts overlap in their description of provider-enabled access, but they are not the same evidentiary process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the dates and attributions differ

Source What it said How to read it
DOJ, 20 December 2018 The defendants’ APT10-related activity allegedly ran from approximately 2006 through approximately 2018; the alleged MSP Theft Campaign began at least around 2014. Claims in an indictment and prosecutorial announcement.
PwC UK and BAE Systems, April 2017 Multiple MSPs were assessed as almost certainly targeted from 2016 onward and likely as early as 2014. A private-sector incident and analytical assessment.
UK government, 20 December 2018 The NCSC assessed APT10 was almost certainly responsible for Cloud Hopper activity against global MSPs since at least 2016. The UK judged the MSS responsible and described an enduring relationship. An intelligence attribution, not a criminal verdict.
NCSC alert, 20 December 2018 APT10 was also known as Stone Panda, MenuPass and Red Apollo; the alert said the group had been active since at least 2009 and warned of continued concern about activity affecting UK sectors. A 2018 government warning. It does not by itself establish present-day activity.

These dates are not contradictory. They reflect different source scopes and standards: a DOJ case history, a private-sector investigation and a government intelligence judgment. “Almost certainly responsible” is the UK’s confidence assessment, not the legal standard applied in the U.S. indictment.

What did the APT10 indictments allege about scale?

The DOJ announcement attached different figures to the two alleged campaigns. Keeping them separate avoids turning one campaign’s statistic into a claim about the other.

Alleged campaign DOJ figure Qualification
Technology Theft Campaign More than 45 technology companies Companies and U.S. government agencies targeted in the earlier campaign.
Technology Theft Campaign At least 12 U.S. states Locations of technology-company victims identified by DOJ.
Technology Theft Campaign Hundreds of gigabytes of sensitive data Data DOJ said was stolen during that campaign.
MSP Theft Campaign At least 12 countries Countries where victim companies were located over the course of the alleged MSP campaign.

Those numbers come from the DOJ’s 2018 description of alleged conduct. The reviewed official material does not provide a separate, reliable market-loss or economic-damage total for Cloud Hopper.

Why MSP compromise has a multiplier effect

A normal intrusion may expose one organization. An MSP intrusion can expose a portfolio of organizations because the provider may hold reusable credentials, persistent remote-management agents, shared monitoring systems, backup access or network routes into customer environments. The provider’s business model creates efficiency for defenders and attackers alike: one technical connection can serve many sites.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That does not mean every MSP compromise automatically compromises every customer. The downstream impact depends on which accounts and tools were reached, whether customers were segmented, how privileges were scoped and how quickly suspicious access was detected. The alleged APT10 sequence illustrates the risk of implicit trust, not a universal outcome.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How organizations can reduce provider-related exposure

The Australian Cyber Security Centre’s guidance, “How to manage your security when engaging a managed service provider”, recommends controls that directly address this attack path. The page was first published on 21 December 2018 and last updated on 6 October 2021; check the source for a newer authoritative revision before treating it as current operational policy.

  • Set contractual expectations. Define security requirements, permitted access, evidence obligations and incident-notification time frames in the MSP contract.
  • Maintain an access inventory. Know which systems, accounts and data each provider can reach, and review that scope regularly as services change.
  • Segment customer and provider networks. Separate MSP management paths from production networks where possible. A secure jump host can provide a controlled, monitored route for administrative work.
  • Use least privilege and attributable accounts. Give technicians only the permissions required for their role, avoid shared accounts and make each administrative action traceable to an individual.
  • Require multifactor authentication. Apply MFA to remotely accessible services and privileged accounts. A compatible FIDO2 security key is one possible factor, but verify that it works with the organization’s identity provider and remote services; no particular brand is endorsed by the cited guidance.
  • Centralize and review logs. Retain relevant provider-access, authentication and administrative activity logs in a location the MSP cannot quietly alter, and investigate unusual times, locations, tools or volume.
  • Prepare for a joint incident. Document who can disable provider access, rotate credentials, isolate systems, preserve evidence, notify customers and communicate publicly if the provider is compromised.

What the 2018 record does—and does not—prove

The record supports a clear historical conclusion: APT10 was accused in a U.S. indictment of using MSP access to reach customers, while the UK separately assessed that the Cloud Hopper activity was almost certainly APT10’s work and attributed responsibility to the MSS. Those statements should be labeled according to their source and evidentiary status.

They do not establish that Zhu Hua or Zhang Shilong were convicted, that every incident associated with the Cloud Hopper label had the same operators, or that the 2018 reports prove current APT10 activity. For present risk decisions, organizations should assess their own provider permissions, segmentation, authentication and monitoring rather than rely on historical attribution alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.