NEW: Group Profiler — instant APT intel lookup. Try it →

Tonto Team

G0131 China MITRE ATT&CK →

Also known as: Earth Akhlut · BRONZE HUNTLEY · CactusPete · Karma Panda

Overview

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

Naming & attribution

Tonto Team is tracked under 5 names across the industry. It uses 15 documented ATT&CK techniques — more than 43% of the 174 groups tracked here. Activity attributed since at least 2009.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Earth AkhlutDaniel Lughi, Jaromir Horejsi
CactusPeteZykov, K
Karma PandaZykov, K
Tonto TeamMercer, W., et al

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA459 China — 4 shared techniques (25% overlap)
  • PLATINUM — 5 shared techniques (24% overlap)
  • Ajax Security Team Iran — 4 shared techniques (24% overlap)
  • Nomadic Octopus Russia — 4 shared techniques (22% overlap)
  • Elderwood China — 4 shared techniques (20% overlap)
  • Whitefly — 4 shared techniques (20% overlap)

Targets

Government · Military · Private sector

Regions

Eastern Europe · Japan · South Korea · Taiwan · United States

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 15 techniques across 10 tactics

Initial Access

Execution

Persistence

Privilege Escalation

Stealth

  • T1574.001 DLL

Credential Access

Discovery

Lateral Movement

Collection

Command and Control

Tools & malware (6)

Mimikatz · Bisonal · ShadowPad · LaZagne · NBTscan · gsecdump

Reporting (3)