Tonto Team

MITRE ATT&CK: G0131 View on attack.mitre.org

Aliases: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, KARMA PANDA, COPPER, Red Beifang, PLA Unit 65017, TAG-74, Tonto Team, Sharp-R

First seen
2009-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-22 00:38:38
Profile updated
2026-07-07 11:46:47

Targeted industries: defense-and-aerospace education-and-nonprofits energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp country_code:tw country_code:us

Context

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

Detection coverage

  • 13 YARA rules
  • 500 Sigma rules

Malware & tools used

  • Network Share Discovery (attack-pattern)
  • DLL (attack-pattern)
  • External Proxy (attack-pattern)
  • Python (attack-pattern)
  • Local Groups (attack-pattern)
  • Keylogging (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • Web Shell (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Malicious File (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • PowerShell (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Bisonal (malware)
  • Mimikatz (malware)
  • gsecdump (malware)
  • NBTscan (malware)
  • LaZagne (malware)
  • ShadowPad (malware)

Reports & references

  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • docs.huihoo.com — Anf T07B The Art Of Attribution Identifying And Pursuing Your Cyber Adversaries Final (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • arstechnica.com — Researchers Claim China Trying To Hack South Korea Missile Defense Efforts (report)
  • Kaspersky — 97962 (report)
  • wsj.com — Chinas Secret Weapon In South Korea Missile Fight Hackers 1492766403 (report)
  • Trend Micro — Supply Chain Attack Targeting Pakistani Government Delivers Shad (report)
  • sentinelone.com — Targets Of Interest Russian Organizations Increasingly Under Attack By Chinese Apts (report)
  • go.recordedfuture.com — Cta 2023 0919 (report)
  • recordedfuture.com — Multi Year Chinese Apt Campaign Targets South Korean Academic Government Political Entities (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G0131 (report)
  • Cisco Talos — Bisonal 10 Years Of Play (report)
  • vb2020.vblocalhost.com — Vb2020 06 (report)
  • web.archive.org — Cds19 Executive S08 Achievement Unlocked (report)
  • CrowdStrike — Adversaries Targeting The Manufacturing Industry (report)
  • secureworks.com — Bronze Huntley (report)
  • trendmicro.de — Wp The Heartbeat Apt Campaign (report)

External references