BRONZE BUTLER
MITRE ATT&CK: G0060 View on attack.mitre.org
Aliases: REDBALDKNIGHT, Tick, Nian, BRONZE BUTLER, STALKER PANDA, Stalker Taurus, PLA Unit 61419, Swirl Typhoon, TELLURIUM, Bronze Butler
- First seen
- 2008-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 103 (101 malicious)
- Last IoC activity
- 2026-09-02 00:38:30
- Profile updated
- 2026-07-07 12:31:14
Targeted industries: government-and-public-sector manufacturing technology-and-telecommunications
Targeted regions: country_code:jp
Context
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.
Recent IoC activity
101 malicious indicators in Maltiverse are attributed to BRONZE BUTLER (G0060). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.nullsecurity.net | 2026-09-03 | 1 |
| hostname | ns-3.open.ro | 2026-09-03 | 1 |
| hostname | autodiscover.email | 2026-09-03 | 1 |
| hostname | autodiscover.exchange | 2026-09-03 | 1 |
| hostname | autoconfig.email | 2026-09-03 | 1 |
| hostname | mail.pics | 2026-09-03 | 1 |
| hostname | prod.tools | 2026-09-02 | 1 |
| hostname | webdisk.us | 2026-09-02 | 1 |
| hostname | autodiscover.host | 2026-09-02 | 1 |
| hostname | admin.dev | 2026-09-02 | 1 |
| hostname | autodiscover.it | 2026-09-02 | 1 |
| hostname | made.by | 2026-09-02 | 1 |
| hostname | www.cantrip.org | 2026-09-02 | 1 |
| hostname | test.support | 2026-09-02 | 1 |
| hostname | mail.news | 2026-09-02 | 1 |
| hostname | webdisk.it | 2026-09-02 | 1 |
| hostname | webdisk.de | 2026-09-02 | 1 |
| hostname | autodiscover.online | 2026-09-02 | 1 |
| hostname | secure.dev | 2026-09-02 | 1 |
| hostname | autodiscover.de | 2026-09-02 | 1 |
Detection coverage
- 13 YARA rules
- 987 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Data from Local System (attack-pattern)
- System Service Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Python (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Screen Capture (attack-pattern)
- Masquerading (attack-pattern)
- Tool (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Visual Basic (attack-pattern)
- Standard Encoding (attack-pattern)
- Software Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Data from Network Shared Drive (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Time Discovery (attack-pattern)
- Drive-by Compromise (attack-pattern)
- DLL (attack-pattern)
- LSASS Memory (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Remote System Discovery (attack-pattern)
- Archive via Utility (attack-pattern)
- At (attack-pattern)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- ESET — Exchange Servers Under Siege 10 Apt Groups (report)
- wikileaks.org — 2015 08 20150814 256 Csir 15005 Stalker Panda (report)
- Broadcom/Symantec — Tick Cyberespionage Group Zeros Japan (report)
- secureworks.jp — Rp Bronze Butler (report)
- researchcenter.paloaltonetworks.com — Unit42 Tick Group Continues Attacks (report)
- blog.jpcert.or.jp — Detecting Datper Malware From Proxy Logs (report)
- cfr.org — Bronze Butler (report)
- secureworks.com — Bronze Butler Targets Japanese Businesses (report)
- Trend Micro — Redbaldknight Bronze Butler Daserf Backdoor Now Using Steganography (report)
- MITRE ATT&CK — G0060 (report)
- secureworks.com — Bronze Butler (report)
- Palo Alto Unit 42 — Stalkertaurus (report)
- twitter.com — 1384431491485155331 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Trend Micro — Redbaldknight Bronze Butler Daserf Backdoor Now Using Steganography (report)
- Trend Micro — Operation Endtrade Tick S Multi Stage Backdoors For Attacking Industries And Stealing Classified Data (report)
External references
- mitre-attack — G0060
- BRONZE BUTLER
- REDBALDKNIGHT
- Tick
- Trend Micro Daserf Nov 2017
- Secureworks BRONZE BUTLER Oct 2017
- Trend Micro Tick November 2019
- Symantec Tick Apr 2016
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy