WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 (TLP:WHITE) Technical Details of APT10’s Intrusion Activities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:WHITE) Technical Details of APT10’s Intrusion Activities

Author: Charles Egli

Created: Thursday, January 3, 2019 - 18:21

Categories: Cybersecurity

The FBI has released a FLASH message regarding information it has obtained on activities performed by a group of malicious cyber actors associated with the Chinese government referred to as “APT10.” On December 20, officials from the U.S. Department of Justice and the U.S. Department of Homeland Security disclosed that they had observed APT10 compromising Managed Service Providers (MSPs), which include Cloud Service Providers (WaterISAC reported on this information that same day, which included a summary in the December 20 SRU). The FLASH includes technical details of the custom tools APT10 has developed and deployed against its targets, which include the REDLEAVES remote access Trojan, the UPPERCUT (aka ANEL) backdoor Trojan, the CHCHES remote access Trojan. The FBI advises that these tools be immediately flagged if detected, reported to the FBI’s Cywatch (cy*****@*bi.gov or 855-292-3937), and given highest priority for enhanced mitigation. The FLASH includes a series of recommended steps for initial mitigation. 

Attached Files:

(U) FBI FLASH - Chinese APT10 intrusion activities target - 20190102

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar