NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / BRONZE BUTLER

BRONZE BUTLER

G0060 China Espionage MITRE ATT&CK →

Also known as: REDBALDKNIGHT · Tick

Overview

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.

Targets

Diplomacy · Engineering · Industrial · Infrastructure · Manufacturing · Media · Political party · Private sector

Regions

China · Japan · Russian Federation · South Korea

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 7 attributed custom malware families

TTPs — 40 techniques across 12 tactics

Resource Development

Initial Access

Execution

Persistence

Privilege Escalation

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Tools & malware (14)

Mimikatz · build_downer · cmd · ABK · at · BBK · schtasks · down_new · Daserf · Net · ShadowPad · Windows Credential Editor · gsecdump · Avenger

Reporting (3)