Tonto Team — APT Profile
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, Copper Typhoon, COPPER, Red Beifang, G0131, PLA Unit 65017, TAG-74, LONE CASTLE
Tools & malware
- Bisonal Backdoor
- gsecdump Credential Harvesting
- LaZagne Credential Harvesting
- Mimikatz Credential Harvesting
- NBTscan Network Reconnaissance
- ShadowPad Backdoor
- win.8t_dropper Loader
- win.calmthorn Backdoor
- win.dexbia Backdoor
- win.korlia Backdoor
- win.quickmute Backdoor
- win.shadowpad Backdoor
- win.typehash Backdoor
Vendor research
- BRONZE HUNTLEY Threat Profile Secureworks
- Manufacturing Industry in the Adversaries’ Crosshairs Crowdstrike
- Exchange servers under siege from at least 10 APT groups ESET
- Bisonal: 10 years of play Talos
- Achievement Unlocked - Chinese Cyber Espionage Evolves to Support Higher Level Missions FireEye
- Tonto Team - Exploring the TTPs of an advanced threat actor operating a large infrastructure TrendMicro
- Researchers claim China trying to hack South Korea missile defense efforts Ars Technica
- CactusPete APT group’s updated Bisonal backdoor Kaspersky
- BRONZE HUNTLEY Threat Profile Secureworks
- The HeartBeat APT Campaign Trend Micro