Also known as: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, Tonto Team, Bisonal (malware), Lone Ranger, COPPER, Red Beifang, G0131, PLA Unit 65017, TAG-74, LONE CASTLE
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).(Citation: Kaspersky CactusPete Aug 2020)(Citation: ESET Exchange Mar 2021)(Citation: FireEye Chinese Espionage October 2019)(Citation: ARS Technica China Hack SK April 2017)(Citation: Trend Micro HeartBeat Campaign January 2013)(Citation: Talos Bisonal 10 Years March 2020)
Targeted Sectors
Executive Summary
The Tonto Team, a suspected Chinese state-sponsored cyber espionage group, has engaged in persistent attacks targeting government, defense, energy, and financial sectors across Asia and Eastern Europe since at least 2009. Known for campaigns like Heartbeat Campaign and Operation Bitter Biscuit, this threat actor employs advanced techniques including spearphishing, malware deployment, and lateral movement to gather sensitive information.
Goals & Targeting
The Tonto Team's primary strategic objective appears to be gathering military, political, and economic intelligence through cyber espionage. This aligns with broader Chinese state interests in regional dominance and technological advancement. Their targeting focus on government agencies, defense contractors, and related sectors suggests they seek sensitive diplomatic, military, and economic data that could provide significant strategic advantages.
Enhanced Description
The Tonto Team is a Chinese state-sponsored cyber espionage group that has been active since at least 2009. This group primarily targets government agencies, defense organizations, energy companies, and financial institutions across South Korea, Japan, Taiwan, the United States, and other Asian and Eastern European countries. The Tonto Team is known to employ sophisticated tactics, including the use of malware such as Bisonal and ShadowPad, as well as campaigns like Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017). These operations demonstrate their ability to infiltrate high-value targets to gather sensitive intelligence. The group's activities highlight the growing threat of state-sponsored cyber espionage targeting critical infrastructure and geopolitical adversaries.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Tonto Team has conducted long-term campaigns such as Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017). These campaigns demonstrate their ability to target multiple sectors over extended periods, indicating a patient and methodical approach to intelligence gathering. Their operational tempo suggests they are resource-rich, likely supported by state infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Tonto Team's state-sponsored nature based on campaign patterns, toolset, and targeting. Gaps remain in fully understanding their operational structure due to the secretive nature of such groups.
No campaigns linked yet.
No observed data linked yet.
15
Techniques
2
Tools
0
Campaigns
2
IOCs
0
Observed Data
10
Tactics