NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Tonto Team

Tonto Team

G0131 China MITRE ATT&CK →

Also known as: Earth Akhlut · BRONZE HUNTLEY · CactusPete · Karma Panda

Overview

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

Targets

Government · Military · Private sector

Regions

Eastern Europe · Japan · South Korea · Taiwan · United States

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 15 techniques across 10 tactics

Initial Access

Execution

Persistence

Privilege Escalation

Stealth

  • T1574.001 DLL

Credential Access

Discovery

Lateral Movement

Collection

Command and Control

Tools & malware (6)

Mimikatz · Bisonal · ShadowPad · LaZagne · NBTscan · gsecdump

Reporting (3)