Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0045
MITRE ATT&CK Group

menuPass (G0045)

CicadaPOTASSIUMStone PandaAPT10Red ApolloCVNXHOGFISHBRONZE RIVERSIDE
ShareXLinkedInRedditHN

[menuPass](https://attack.mitre.org/groups/G0045) is a threat group that has been active since at least 2006. Individual members of [menuPass](https://attack.mitre.org/groups/G0045) are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018) [menuPass](https://attack.mitre.org/groups/G0045) has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.(Citation: Palo Alto menuPass Feb 2017)(Citation: Crowdstrike CrowdCast Oct 2013)(Citation: FireEye Poison Ivy)(Citation: PWC Cloud Hopper April 2017)(Citation: FireEye APT10 April 2017)(Citation: DOJ APT10 Dec 2018)(Citation: District Court of NY APT10 Indictment December 2018)

▪Techniques used (46)

T1018Remote System DiscoveryT1047Windows Management InstrumentationT1036MasqueradingT1070.004File DeletionT1046Network Service DiscoveryT1049System Network Connections DiscoveryT1560.001Archive via UtilityT1566.001Spearphishing AttachmentT1105Ingress Tool TransferT1588.002ToolT1204.002Malicious FileT1090.002External ProxyT1078Valid AccountsT1016System Network Configuration DiscoveryT1568.001Fast Flux DNST1036.003Rename Legitimate UtilitiesT1056.001KeyloggingT1087.002Domain AccountT1003.003NTDST1218.004InstallUtilT1106Native APIT1003.002Security Account ManagerT1027.013Encrypted/Encoded FileT1199Trusted RelationshipT1190Exploit Public-Facing ApplicationT1074.002Remote Data StagingT1070.003Clear Command HistoryT1140Deobfuscate/Decode Files or InformationT1553.002Code SigningT1053.005Scheduled TaskT1055.012Process HollowingT1074.001Local Data StagingT1021.001Remote Desktop ProtocolT1039Data from Network Shared DriveT1003.004LSA SecretsT1083File and Directory DiscoveryT1036.005Match Legitimate Resource Name or LocationT1560Archive Collected DataT1059.003Windows Command ShellT1005Data from Local SystemT1059.001PowerShellT1210Exploitation of Remote ServicesT1021.004SSHT1119Automated CollectionT1583.001DomainsT1574.001DLL

▪Software used (25)

S0160certutiltoolS0628FYAntimalwareS0275UPPERCUTmalwareS0159SNUGRIDEmalwareS0626P8RATmalwareS0153RedLeavesmalwareS0627SodaMastermalwareS0006pwdumptoolS0002MimikatztoolS0013PlugXmalwareS0039NettoolS0194PowerSploittoolS0144ChChesmalwareS0106cmdtoolS0262QuasarRATtoolS0552AdFindtoolS0154Cobalt StrikemalwareS0012PoisonIvymalwareS0152EvilGrabmalwareS0404esentutltoolS0357ImpackettoolS0624EcipekacmalwareS0097PingtoolS0029PsExectoolS1097HUI Loadermalware
G0045on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.