Tonto Team
MITRE ATT&CK: G0131 View on attack.mitre.org
Aliases: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, KARMA PANDA, COPPER, Red Beifang, PLA Unit 65017, TAG-74, Tonto Team, Sharp-R
- First seen
- 2009-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-22 00:38:38
- Profile updated
- 2026-07-07 11:46:47
Targeted industries: defense-and-aerospace education-and-nonprofits energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:kr country_code:jp country_code:tw country_code:us
Context
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).
Detection coverage
- 13 YARA rules
- 500 Sigma rules
Malware & tools used
- Network Share Discovery (attack-pattern)
- DLL (attack-pattern)
- External Proxy (attack-pattern)
- Python (attack-pattern)
- Local Groups (attack-pattern)
- Keylogging (attack-pattern)
- OS Credential Dumping (attack-pattern)
- Web Shell (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Malicious File (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- PowerShell (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Bisonal (malware)
- Mimikatz (malware)
- gsecdump (malware)
- NBTscan (malware)
- LaZagne (malware)
- ShadowPad (malware)
Reports & references
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- docs.huihoo.com — Anf T07B The Art Of Attribution Identifying And Pursuing Your Cyber Adversaries Final (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- ESET — Exchange Servers Under Siege 10 Apt Groups (report)
- arstechnica.com — Researchers Claim China Trying To Hack South Korea Missile Defense Efforts (report)
- Kaspersky — 97962 (report)
- wsj.com — Chinas Secret Weapon In South Korea Missile Fight Hackers 1492766403 (report)
- Trend Micro — Supply Chain Attack Targeting Pakistani Government Delivers Shad (report)
- sentinelone.com — Targets Of Interest Russian Organizations Increasingly Under Attack By Chinese Apts (report)
- go.recordedfuture.com — Cta 2023 0919 (report)
- recordedfuture.com — Multi Year Chinese Apt Campaign Targets South Korean Academic Government Political Entities (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G0131 (report)
- Cisco Talos — Bisonal 10 Years Of Play (report)
- vb2020.vblocalhost.com — Vb2020 06 (report)
- web.archive.org — Cds19 Executive S08 Achievement Unlocked (report)
- CrowdStrike — Adversaries Targeting The Manufacturing Industry (report)
- secureworks.com — Bronze Huntley (report)
- trendmicro.de — Wp The Heartbeat Apt Campaign (report)
External references
- mitre-attack — G0131
- CactusPete
- Karma Panda
- BRONZE HUNTLEY
- Tonto Team
- Earth Akhlut
- TrendMicro Tonto Team October 2020
- CrowdStrike Manufacturing Threat July 2020
- ESET Exchange Mar 2021
- Talos Bisonal Mar 2020
- FireEye Chinese Espionage October 2019
- Trend Micro HeartBeat Campaign January 2013
- ARS Technica China Hack SK April 2017
- Secureworks BRONZE HUNTLEY
- Talos Bisonal 10 Years March 2020
- Kaspersky CactusPete Aug 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy