MenuPass — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 9, 2026
Last Seen
July 1, 2026

MenuPass is a apt_group tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 9, 2026; most recent activity July 1, 2026.

Overview

MenuPass is an APT group associated with the China-Nexus espionage ecosystem, described as conducting targeted espionage campaigns. Reports link MenuPass to operations against telecommunications operators in South Asia, highlighting its focus on critical infrastructure and intelligence collection. This underscores ongoing state-linked activity targeting regional telecom networks for strategic gain.

Related Threat Clusters

Recent Intelligence Reports

  • 012 — attack.mitre.org · July 1, 2026
  • MITRE ATT&CK T1199 — attack.mitre.org · May 26, 2026
  • T1005 — attack.mitre.org · April 22, 2026
  • China-Nexus Espionage APT Targets South Asia Telecoms — Technadu · January 9, 2026

CVSS v3.1 Breakdown