Tonto Team — APT Profile

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

Also tracked as

Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, Copper Typhoon

Tools & malware

Vendor research

Read the full analysis on IntelFusions