BRONZE BUTLER

MITRE ATT&CK: G0060 View on attack.mitre.org

Aliases: REDBALDKNIGHT, Tick, Nian, BRONZE BUTLER, STALKER PANDA, Stalker Taurus, PLA Unit 61419, Swirl Typhoon, TELLURIUM, Bronze Butler

First seen
2008-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
103 (101 malicious)
Last IoC activity
2026-09-02 00:38:30
Profile updated
2026-07-07 12:31:14

Targeted industries: government-and-public-sector manufacturing technology-and-telecommunications

Targeted regions: country_code:jp

Context

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.

Recent IoC activity

101 malicious indicators in Maltiverse are attributed to BRONZE BUTLER (G0060). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.nullsecurity.net 2026-09-03 1
hostname ns-3.open.ro 2026-09-03 1
hostname autodiscover.email 2026-09-03 1
hostname autodiscover.exchange 2026-09-03 1
hostname autoconfig.email 2026-09-03 1
hostname mail.pics 2026-09-03 1
hostname prod.tools 2026-09-02 1
hostname webdisk.us 2026-09-02 1
hostname autodiscover.host 2026-09-02 1
hostname admin.dev 2026-09-02 1
hostname autodiscover.it 2026-09-02 1
hostname made.by 2026-09-02 1
hostname www.cantrip.org 2026-09-02 1
hostname test.support 2026-09-02 1
hostname mail.news 2026-09-02 1
hostname webdisk.it 2026-09-02 1
hostname webdisk.de 2026-09-02 1
hostname autodiscover.online 2026-09-02 1
hostname secure.dev 2026-09-02 1
hostname autodiscover.de 2026-09-02 1

Detection coverage

  • 13 YARA rules
  • 987 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Service Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Python (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Screen Capture (attack-pattern)
  • Masquerading (attack-pattern)
  • Tool (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Visual Basic (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Software Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Network Shared Drive (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • DLL (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Archive via Utility (attack-pattern)
  • At (attack-pattern)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • wikileaks.org — 2015 08 20150814 256 Csir 15005 Stalker Panda (report)
  • Broadcom/Symantec — Tick Cyberespionage Group Zeros Japan (report)
  • secureworks.jp — Rp Bronze Butler (report)
  • researchcenter.paloaltonetworks.com — Unit42 Tick Group Continues Attacks (report)
  • blog.jpcert.or.jp — Detecting Datper Malware From Proxy Logs (report)
  • cfr.org — Bronze Butler (report)
  • secureworks.com — Bronze Butler Targets Japanese Businesses (report)
  • Trend Micro — Redbaldknight Bronze Butler Daserf Backdoor Now Using Steganography (report)
  • MITRE ATT&CK — G0060 (report)
  • secureworks.com — Bronze Butler (report)
  • Palo Alto Unit 42 — Stalkertaurus (report)
  • twitter.com — 1384431491485155331 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Trend Micro — Redbaldknight Bronze Butler Daserf Backdoor Now Using Steganography (report)
  • Trend Micro — Operation Endtrade Tick S Multi Stage Backdoors For Attacking Industries And Stealing Classified Data (report)

External references