CSIDB logo
Threat actor

Zhu Hua

Attribution profile

Type
Nation State
Location
China
Known incidents
3 incidents
First seen
2006-01-01
Last seen
2006-01-01
Updated
2026-07-23 00:14
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Zhu Hua is an alias used by a Chinese state‑sponsored threat actor publicly linked to the APT10 hacking group. The individual, together with a compatriot, was charged by the United States Department of Justice for conducting cyber espionage on behalf of China’s Ministry of State Security. This actor operates as part of a broader campaign that has been active for over a decade, focusing on the theft of intellectual property and confidential business data. The activity is not financially motivated but serves strategic intelligence goals for the Chinese government.

The actor’s typical targets include managed service providers, technology firms, and government entities located in North America, Europe, and Asia. Sectors most frequently mentioned in public reports are aviation, satellite technology, healthcare, telecommunications, energy exploration, biotechnology, and industrial automation. By compromising MSPs the actor gains a foothold that allows movement into the networks of the providers’ clients across these industries. The primary objective is the acquisition of proprietary technological and commercial secrets to support state‑led economic and military advancement.

Reported tactics involve the initial compromise of managed service providers through unspecified means, after which stolen credentials are used to authenticate and pivot into customer networks. The actor leverages the compromised infrastructure to maintain persistent access and to exfiltrate large volumes of data, with descriptions citing the theft of hundreds of gigabytes of information. No specific malware families or custom tooling are detailed in the available sources, so the emphasis is on credential abuse and living‑off‑the‑land techniques. These methods enable prolonged, low‑detection operations that can span several years.

Attribution to the Chinese state is explicit in the charging documents, which identify the two individuals as acting in conjunction with the Ministry of State Security. The actor is publicly associated with the APT10 group, a label used by security researchers to describe a set of activities tied to Chinese intelligence. No connection to criminal syndicates or financially motivated hacking crews is indicated in the material. The state nexus is therefore the only confirmed affiliation for Zhu Hua.

A representative operation described in the sources is a decade‑long espionage campaign that targeted more than forty‑five companies and government agencies, including a U.S. space research center identified as a NASA facility. Through the compromise of managed service providers the actor accessed satellite technology, aviation, healthcare, telecommunications, and energy networks, removing large volumes of proprietary data. The campaign also extended to biotechnology and industrial automation sectors, demonstrating a broad interest in high‑value technical information. These activities illustrate the actor’s capability to conduct sustained, global intrusions aimed at strategic intelligence gathering.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB