The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Operation Cloud Hopper was a cyber-espionage campaign in which attackers targeted managed service providers (MSPs) to reach selected customers through trusted service connections. Compromising a provider could expose multiple downstream organizations, but the campaign reports do not establish that every MSP or customer was affected.
How Operation Cloud Hopper worked
PwC UK and BAE Systems described a sustained campaign against MSPs. They said multiple providers were almost certainly targeted from 2016 onward and may have been targeted as early as 2014. The investigators began assisting victims in late 2016. Their report also describes a separate, simultaneous campaign that directly targeted Japanese organizations, rather than using an MSP as the entry point. PwC UK and BAE Systems’ April 2017 report
The MSP route mattered because providers commonly have legitimate access to customers’ systems to deliver IT services. In the investigators’ reported sequence, the actor first compromised an MSP, then used provider access to reach customers that matched its targeting profile. It moved laterally to data of interest, staged and compressed collected material, moved it back through the MSP network, and exfiltrated it to actor-controlled infrastructure. This is the methodology investigators described; it is not proof that every step occurred at every victim.
MSP compromise versus direct targeting
| Approach | Initial target | Path to victim information | Potential reach |
|---|---|---|---|
| Operation Cloud Hopper’s MSP route | A managed IT provider | Trusted service access from the provider into selected customer networks | Multiple downstream customers could be exposed through one provider, depending on its access |
| Direct targeting described in the 2017 report | Japanese organizations | Direct compromise of the organizations themselves | The organizations targeted directly; the report treats this as a separate campaign |
Who was behind the campaign?
PwC UK and BAE Systems assessed in 2017 that the actor was almost certainly the group widely known as APT10 and highly likely to be China-based. Their assessment drew on activity patterns, infrastructure, compile and domain-registration timing, and targeting. It is an attribution assessment, not a claim that each technical detail independently proves the actor’s identity.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
In December 2018, the UK National Cyber Security Centre (NCSC) said the UK and its allies announced that APT10 acted on behalf of China’s Ministry of State Security in a campaign targeting intellectual property and sensitive commercial data. NCSC: APT10 continuing to target UK organisations
Group names vary across security companies and reporting. PwC’s report associates APT10 with names including Red Apollo, CVNX, Stone Panda, and menuPass Team. MITRE ATT&CK’s menuPass (G0045) profile, version 3.0, last modified 31 July 2026, lists APT10, Stone Panda, Red Apollo, and CVNX among associated names. These labels overlap, but vendor and agency cluster definitions should not be assumed to match exactly. MITRE ATT&CK: menuPass (G0045)
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
What the investigators observed
The following technical details describe observations reported in 2017, not a current threat bulletin or a list of indicators known to be active today.
Malware and access
The technical annex distinguishes tactical malware, used to gain a foothold, from sustained malware that helped maintain access and function as a backdoor. Tactical families were often delivered through spear-phishing and supported system identification and lateral movement. The main report identifies PlugX as the primary malware from 2014 to 2016, followed by bespoke malware and customized open-source tools. PwC UK, Operation Cloud Hopper: Technical Annex (April 2017)
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Espionage targets and impact
The original investigators characterized the campaign as espionage focused on intellectual property and other sensitive information. They described collected data moving through complex exfiltration routes that could involve multiple victim networks. A later NCSC update lists healthcare, defence, aerospace, government, heavy industry and mining, MSPs, and IT among sectors targeted by APT10 for likely intellectual-property theft.
The Australian Cyber Security Centre (ACSC) separately documented theft of commercial secrets and information from the Australian arm of a multinational construction services company through its MSP. The agency said the tactics, techniques, and procedures it observed aligned with the public Operation Cloud Hopper report. Its case illustrates the risk of provider access; it does not establish that every incident attributed to APT10 followed an identical path. ACSC: MSP Investigation Report
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
What organizations can learn from Cloud Hopper
The durable lesson is about access and trust: an MSP connection can be a route into customer systems, so both sides need to limit and monitor what that connection can reach. These safeguards address the exposure illustrated by the historical campaign; they are not a claim that Cloud Hopper’s reported malware remains active.
- Map provider access. Identify which systems, accounts, and data each MSP can reach, including remote-management tools and administrative accounts. Revisit access when a service or provider changes.
- Limit privileges. Give provider accounts only the permissions needed for their tasks. Avoid broad, persistent administrator access where narrower roles or time-limited access will work.
- Segment valuable systems. Separate sensitive networks and information so that a compromised provider connection does not automatically grant access to everything. Restrict and log connections between segments.
- Monitor provider activity. Review authentication, remote-management, and data-transfer logs for unusual access patterns, especially activity outside expected systems or service windows.
- Agree on incident response before an incident. Establish who will investigate, preserve logs, notify affected parties, and coordinate containment if either the provider or customer suspects compromise. Organizations without in-house expertise may need specialist investigation.
- Use government guidance when engaging an MSP. The ACSC’s MSP material includes guidance for managing security when engaging a provider. ACSC guidance for managed service providers
Why Cloud Hopper is still relevant—and what it does not tell you
Cloud Hopper remains a useful historical example of how a trusted IT relationship can extend an attacker’s reach beyond the organization first compromised. Its reported timeline, malware families, and infrastructure belong to investigators’ observations from that period. They should not be treated as evidence of current activity, nor used alone to determine whether an organization is compromised now.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
For a present-day assessment, organizations need current telemetry and threat intelligence, together with a review of provider access and security controls. The campaign’s core risk is structural: when an MSP can reach customer networks, security depends in part on how that access is scoped, monitored, and protected.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

