Advanced Persistent Threat 10 – Chinese State-Sponsored
Executive Summary
APT10 (also known as Stone Panda, APT10, Stone Panda, G0004) is a Chinese state-sponsored advanced persistent threat group primarily focused on espionage, critical infrastructure targeting, and government institutions. This report covers their operations as of 2026, including their recent campaigns, tools, TTPs, and target sectors.


Basic Information
- Name: APT10 (Stone Panda)
- Aliases: APT10, Stone Panda, G0004
- MITRE ATT&CK Group ID: G0004
- Country of Origin: China
- Threat Level: HIGH
- Primary Motivation: State-sponsored espionage, critical infrastructure targeting, government institutions

Recent Operations (2025-2026)
Russian State-Owned Defense (2025-2026):
- Russian state-owned defense institutes targeting
- Defense contractor operations
- Military equipment vendor operations
- Research institute compromise
Critical Infrastructure (2025-2026):
- Energy sector operations
- Transportation sector targeting
- Government institution compromise
- Scientific data theft
Primary Tools:
- Cobalt Strike (primary post-exploitation)
- Custom malware (Stone Panda framework)
- Spearphishing campaigns
- Zero-day exploitation
- Credential dumping (Mimikatz, BloodHound)

TTPs (MITRE ATT&CK Mapping)
Initial Access:
- Phishing (Spearphishing Link, Spearphishing Attachment)
- Exploit publicly available vulnerabilities
- Supply chain compromise
Execution:
- Browser Execution
- PowerShell
- Command and Scripting Interpreter
Persistence:
- Boot/Logon Autostart
- Accessibility Features
- Lateral Tool Transfer
Privilege Escalation:
- Exploitation for Privilege Escalation
- Abuse Elevation Control Mechanism
Defense Evasion:
- Indicator Removal
- File and Directory Permissions Modification
- Obfuscated Files or Information
Credential Access:
- Credential Dumping (LSASS Memory)
- Remote Service Discovery
Discovery:
- Active Directory Enumeration
- Network Service Discovery
Lateral Movement:
- Remote Services (RDP, SMB)
- Remote Services (SMB)
Collection:
- Data from Local System
- Data from Network
Exfiltration:
- Exfiltration Over C2 Channel
- Exfiltration Over Alternative Protocol

Known Campaigns (2025-2026)
Operation 1 (2025):
- Target: Russian state-owned defense institutes
- Impact: Defense technology espionage
- Tools: Cobalt Strike, custom malware
Operation 2 (2025):
- Target: Critical infrastructure
- Impact: Industrial control system targeting
- Tools: Cobalt Strike, Mimikatz
Operation 3 (2026):
- Target: Government institutions
- Impact: Political influence, information warfare
- Tools: Cobalt Strike, spearphishing

Threat Assessment
Threat Level: HIGH
Primary Targets:
- Russian state-owned defense
- Critical infrastructure
- Government institutions
- Scientific research
Capabilities:
- Advanced persistent threat
- Critical infrastructure targeting
- Multi-vector attacks
- Long-term persistence
- Supply chain attacks

Sources
- Industrial Cyber
- CISA Advisories
- MITRE ATT&CK
- CISA AA26-097A
- CrowdStrike Threat Intelligence
- Mandiant Reports
- FortiGuard Labs
- Brandefense

Report Generated: 2026-06-10
Intelligence Freshness: Current (as of June 2026)
Classification: Unclassified
