Cloud Hopper never really ended. It evolved.
APT10 (attributed to China’s Ministry of State Security and publicly designated by the UK government, CISA, and the US Department of Justice in 2018) has resumed systematic targeting of UK and European managed service providers. The methodology is the same one that gave the group simultaneous access to client environments across 12 countries during the original campaign: compromise the MSP, then use its delegated access to reach every client in its portfolio.
Why This Approach Keeps Working
The original Cloud Hopper campaign documented from 2016 was notable for two things: its patience and its leverage. APT10 didn’t break into aerospace companies, pharmaceutical firms, or government contractors individually. It compromised the MSPs that managed IT for those organisations, then accessed client environments using the MSP’s own privileged credentials and network trust relationships. One MSP compromise, potentially dozens of client breaches. The economics are compelling.
That logic scales even better in the cloud era. An MSP managing Microsoft 365, Azure, or AWS tenants for a portfolio of clients holds delegated administrator credentials across all of them. APT10 is now targeting the management plane itself (the portals and tooling MSPs use to administer client tenants) rather than each client individually.
RMM platforms (ConnectWise, TeamViewer, N-able) are being abused as access mechanisms following initial credential compromise. These tools generate high volumes of legitimate-looking activity. An actor using a compromised MSP admin account through a standard RMM platform blends into the normal operational background in ways that novel malware would not.
APT10 is not collecting indiscriminately. Activity indicates selective targeting of MSP clients with R&D programmes, defence contracts, or government-adjacent work, consistent with Chinese state intelligence collection priorities. Not every client gets attention. The ones that do are selected.
Professional Services in the Blast Radius
Law firms, accountancies, and management consultancies that outsource IT delivery to managed service providers are downstream targets. Not because they are attacked directly, but because their MSP’s compromise is their compromise.
Firms with exposure are those that have been publicly involved in government contracts, M&A transactions in sectors of Chinese interest, regulatory proceedings affecting Chinese businesses, or R&D advisory work. The 2018 Cloud Hopper attribution included professional services among the affected sectors. Nothing in the intervening period suggests that interest has diminished.
The problem is that most professional services firms have no visibility into what their MSP’s access model looks like from an adversary’s perspective. They know what services they’re paying for. They don’t know what credentials their MSP holds, what those credentials can reach, or whether the MSP has segregated their environment from other clients.
What Clients of MSPs Need to Know
Understand precisely what delegated permissions your MSP holds in your cloud tenants. Not what they say they need, but what they actually have. Pull the delegated admin relationships in your Entra ID and review them. This conversation with your MSP is worth having before something happens, not after.
Phishing-resistant MFA on MSP admin accounts is non-negotiable. Delegated administrator access without hardware key or passkey authentication is a single credential theft away from full tenant access. That applies to both sides: your tenant’s admin accounts and your MSP’s internal accounts.
MSP security posture needs to be in your supplier assurance programme. Your IT delivery depends on their security. If they’re compromised, you’re compromised. What are their security accreditations? What are their incident reporting obligations to you contractually? Do you have a right to audit? Most service agreements written before 2020 are silent on this.
Log all administrative actions performed by MSP accounts. Lateral movement or data access outside normal support patterns looks different from ticket-driven maintenance work, if you’re capturing and reviewing that activity. Most organisations aren’t. That’s the gap.