46
Techniques
25
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company. menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.

View MITRE record ↗

Techniques by Tactic (46)
Defence Impairment
Toolsets (25)
🐛
ChChes S0144
Malware · Windows
🐛
Malware · Linux, macOS, Windows
🐛
Ecipekac S0624
Malware · Windows
🐛
EvilGrab S0152
Malware · Windows
🐛
FYAnti S0628
Malware · Windows
🐛
Malware · Windows
🐛
P8RAT S0626
Malware · Windows
🐛
PlugX S0013
Malware · Windows
🐛
PoisonIvy S0012
Malware · Windows
🐛
RedLeaves S0153
Malware · Windows
🐛
SNUGRIDE S0159
Malware · Windows
🐛
Malware · Windows
🐛
UPPERCUT S0275
Malware · Windows
🔧
AdFind S0552
Tool · Windows
🔧
Impacket S0357
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Net S0039
Tool · Windows
🔧
Ping S0097
Tool
🔧
Tool · Windows
🔧
PsExec S0029
Tool · Windows
🔧
QuasarRAT S0262
Tool · Windows
🔧
certutil S0160
Tool · Windows
🔧
cmd S0106
Tool · Windows
🔧
esentutl S0404
Tool · Windows
🔧
pwdump S0006
Tool · Windows
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2017-0176View full details on NVD
↑