BRONZE BUTLER — APT Profile
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
REDBALDKNIGHT, Tick, TempTick, TEMP.Tick, Stalker Panda, Nian, G0060, Stalker Taurus, PLA Unit 61419, Swirl Typhoon, TICK CASTLE
IntelFusions coverage (1)
- Phishing kit uses AI to check the IDs it steals from you 2026-08-14 · AI Security
Tools & malware
- ABK Backdoor
- at Execution
- Avenger Backdoor
- BBK Backdoor
- build_downer Backdoor
- cmd Execution
- Daserf Backdoor
- Datper backdoor
- down_new Backdoor
- Gofarer downloader
- gsecdump Credential Harvesting
- HomamDownloader downloader
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- schtasks Persistence
- ShadowPad Backdoor
- SymonLoader loader
- Windows Credential Editor Credential Harvesting
- xxmm backdoor
Vendor research
- BRONZE BUTLER Targets Japanese Businesses Secureworks
- Tick Group Weaponized Secure USB Drives to Target Air-Gapped Critical Systems Palo Alto Networks Unit 42
- “Tick” Group Continues Attacks Palo Alto Networks Unit 42
- BRONZE BUTLER Targets Japanese Enterprises Counter Threat Unit Research Team
- REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography Trend Micro
- Tick cyberespionage group zeros in on Japan Symantec
- Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data Trend Micro
- BRONZE BUTLER Targets Japanese Enterprises Secureworks
Countries linked to this actor
- Japan targets