WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:WHITE) Technical Details of APT10’s Intrusion Activities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:WHITE) Technical Details of APT10’s Intrusion Activities

Author: Charles Egli

Created: Thursday, January 3, 2019 - 18:21

Categories: Cybersecurity

The FBI has released a FLASH message regarding information it has obtained on activities performed by a group of malicious cyber actors associated with the Chinese government referred to as “APT10.” On December 20, officials from the U.S. Department of Justice and the U.S. Department of Homeland Security disclosed that they had observed APT10 compromising Managed Service Providers (MSPs), which include Cloud Service Providers (WaterISAC reported on this information that same day, which included a summary in the December 20 SRU). The FLASH includes technical details of the custom tools APT10 has developed and deployed against its targets, which include the REDLEAVES remote access Trojan, the UPPERCUT (aka ANEL) backdoor Trojan, the CHCHES remote access Trojan. The FBI advises that these tools be immediately flagged if detected, reported to the FBI’s Cywatch (cy*****@*bi.gov or 855-292-3937), and given highest priority for enhanced mitigation. The FLASH includes a series of recommended steps for initial mitigation. 

Attached Files:

(U) FBI FLASH - Chinese APT10 intrusion activities target - 20190102

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar