CARDS
CARDS
Historical public reporting connects APT10/menuPass to credential theft, managed-service-provider and downstream-client access, DLL side-loading, PlugX-family tooling, and Japan-linked espionage. These actor links provide context but do not attribute every SOGU or PlugX-family intrusion.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Entity Type1
Not identified as a standalone RaaS brand in this seed row.
First Seen1
2017-05-31
Last Seen1
ATT&CK record modified 2026-05-12; operational last-seen varies by source
Profile Updated1
2026-08-06T16:00:00.000Z
Victim Count
Not available
Origin1
Unknown
Motivation1
Espionage / strategic intelligence collection
Primary Access Pattern1
T1078 Valid Accounts
Objective1
Espionage / strategic intelligence collection
Identity
Aliases1
Source Boundary
Retained source record is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure
Target Sectors
Associated Activity1
ATT&CK IDs1
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
Source coverage: 2 source groups tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar | N/A | 0 | Profile retained; no SOCRadar IOC count currently stored. |
| MITRE ATT&CK / CTI1 | N/A | 0 | Technique and identity context retained; not treated as raw IOC feed for this card. |
IntelliOS Intel Products
PANDA Flash Threat Intel Brief
Source-backed investigation and response brief for credential- and provider-trust-led access, DLL side-loading, memory collection, and proof criteria.
CARDS Campaign
Campaign record with explicit attribution and CVE relationship boundaries.
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| Retained source record | menuPass | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | menuPass | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | MITRE ATT&CK https://attack.mitre.org/groups/G0045/ | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 2 | SOGU Flash Threat Brief /vault/sogu-plugx-remote-access-malware | IntelliOS Flash Threat Brief |
| 3 | PLUGX/SOGU Multi-Victim Intrusions /threat-actor-cards/campaigns/plugx-sogu-multi-victim-intrusions | CARDS Campaign |
| 4 | CISA multi-victim intrusion alert https://www.cisa.gov/sites/default/files/publications/IR-ALERT-MED-17-093-01C-Intrusions_Affecting_Multiple_Victims_Across_Multiple_Sectors.pdf | Government Alert |
| 5 | DOJ: APT10 global intrusion campaigns https://www.justice.gov/usao-sdny/pr/two-chinese-hackers-associated-ministry-state-security-charged-global-computer | Government Attribution |
| 6 | Symantec: Cicada/APT10 Japan-linked campaign https://www.security.com/threat-intelligence/cicada-apt10-japan-espionage | Primary Campaign Research |
| 7 | Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018. http://web.archive.org/web/20220810112638/https:/www.accenture.com/t20180423T055005Z_w_/se-en/_acnmedia/PDF-76/Accenture-Hogfish-Threat-Analysis.pdf | Accenture Hogfish April 2018 |
| 8 | Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS... https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader | SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022 |
| 9 | Crowdstrike. (2013, October 16). CrowdCasts Monthly: You Have an Adversary Problem.... https://www.slideshare.net/slideshow/crowd-casts-monthly-you-have-an-adversary-problem/27262315 | Crowdstrike CrowdCast Oct 2013 |
| 10 | FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global... https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html | FireEye APT10 April 2017 |
| 11 | FireEye. (2014). POISON IVY: Assessing Damage and Extracting Intelligence. Retrieved... https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf | FireEye Poison Ivy |
| 12 | Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using... https://www.fireeye.com/blog/threat-research/2018/09/apt10-targeting-japanese-corporations-using-updated-ttps.html | FireEye APT10 Sept 2018 |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for menuPass.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |