Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Tonto Team

Also known as: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, Tonto Team, Bisonal (malware), Lone Ranger, COPPER, Red Beifang, G0131, PLA Unit 65017, TAG-74, LONE CASTLE

Description

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).(Citation: Kaspersky CactusPete Aug 2020)(Citation: ESET Exchange Mar 2021)(Citation: FireEye Chinese Espionage October 2019)(Citation: ARS Technica China Hack SK April 2017)(Citation: Trend Micro HeartBeat Campaign January 2013)(Citation: Talos Bisonal 10 Years March 2020)

Goals & Targeting

Targeted Sectors

Defense
Government

AI Analysis

· 1 week ago

Executive Summary

The Tonto Team, a suspected Chinese state-sponsored cyber espionage group, has engaged in persistent attacks targeting government, defense, energy, and financial sectors across Asia and Eastern Europe since at least 2009. Known for campaigns like Heartbeat Campaign and Operation Bitter Biscuit, this threat actor employs advanced techniques including spearphishing, malware deployment, and lateral movement to gather sensitive information.

Goals & Targeting

The Tonto Team's primary strategic objective appears to be gathering military, political, and economic intelligence through cyber espionage. This aligns with broader Chinese state interests in regional dominance and technological advancement. Their targeting focus on government agencies, defense contractors, and related sectors suggests they seek sensitive diplomatic, military, and economic data that could provide significant strategic advantages.

Enhanced Description

The Tonto Team is a Chinese state-sponsored cyber espionage group that has been active since at least 2009. This group primarily targets government agencies, defense organizations, energy companies, and financial institutions across South Korea, Japan, Taiwan, the United States, and other Asian and Eastern European countries. The Tonto Team is known to employ sophisticated tactics, including the use of malware such as Bisonal and ShadowPad, as well as campaigns like Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017). These operations demonstrate their ability to infiltrate high-value targets to gather sensitive intelligence. The group's activities highlight the growing threat of state-sponsored cyber espionage targeting critical infrastructure and geopolitical adversaries.

Key Capabilities

  • State-sponsored cyber espionage
  • Advanced persistent threat (APT) capabilities
  • Spear-phishing campaigns
  • Malware deployment (Bisonal, ShadowPad)
  • Lateral movement and privilege escalation techniques
  • DLL injection and web shell usage
  • Exploitation of remote services

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Defense Evasion
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1056.001: Keylogging
T1003: OS Credential Dumping
T1204.002: Malicious File
T1574.001: DLL
T1135: Network Share Discovery
T1505.003: Web Shell
T1090.002: External Proxy
T1068: Exploitation for Privilege Escalation
T1203: Exploitation for Client Execution
T1059.001: PowerShell

Software / Tooling

Bisonal (malware)
ShadowPad
PowerShell scripts
Python-based tools

Campaigns & Victims

The Tonto Team has conducted long-term campaigns such as Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017). These campaigns demonstrate their ability to target multiple sectors over extended periods, indicating a patient and methodical approach to intelligence gathering. Their operational tempo suggests they are resource-rich, likely supported by state infrastructure.

IOC Patterns

  • Spear-phishing emails
  • Malicious Office documents
  • DLL injection attacks
  • Web shell deployment
  • OS credential dumping
  • Network share enumeration

Recommended Actions

  • Implement robust email filtering and phishing detection solutions.
  • Monitor for unusual network activity, particularly web shell usage and external proxy connections.
  • Conduct regular vulnerability assessments to mitigate remote service exploitation attempts.
  • Enhance endpoint detection and response capabilities to detect malicious file activities.
  • Apply strong access controls and monitoring to sensitive data repositories and network shares.

Suggested Tags

APT
espionage
state-sponsored
government
defense
China

Confidence Assessment

High confidence in Tonto Team's state-sponsored nature based on campaign patterns, toolset, and targeting. Gaps remain in fully understanding their operational structure due to the secretive nature of such groups.

ATT&CK Techniques

Execution
4 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. TrendMicro Tonto Team October 2020 — Daniel Lughi, Jaromir Horejsi. (2020, October 2). Tonto Team - Exploring the TTPs of an advanced threat actor operating a large infrastructure. Retrieved October 17, 2021.
  2. CrowdStrike Manufacturing Threat July 2020 — Falcon OverWatch Team. (2020, July 14). Manufacturing Industry in the Adversaries’ Crosshairs. Retrieved October 17, 2021.
  3. ESET Exchange Mar 2021 — Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021.
  4. Talos Bisonal Mar 2020 — Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.
  5. FireEye Chinese Espionage October 2019 — Nalani Fraser, Kelli Vanderlee. (2019, October 10). Achievement Unlocked - Chinese Cyber Espionage Evolves to Support Higher Level Missions. Retrieved November 17, 2024.
  6. Trend Micro HeartBeat Campaign January 2013 — Roland Dela Paz. (2003, January 3). The HeartBeat APT Campaign. Retrieved October 17, 2021.
  7. ARS Technica China Hack SK April 2017 — Sean Gallagher. (2017, April 21). Researchers claim China trying to hack South Korea missile defense efforts. Retrieved October 17, 2021.
  8. Secureworks BRONZE HUNTLEY — Secureworks. (2021, January 1). BRONZE HUNTLEY Threat Profile. Retrieved May 5, 2021.
  9. Kaspersky CactusPete Aug 2020 — Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.

Intel Summary

15

Techniques

2

Tools

0

Campaigns

2

IOCs

0

Observed Data

10

Tactics

Tags

APT
Healthcare Targeting
Government Targeting
espionage
state-sponsored
government
defense
China

Details

MITRE ID
G0131
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c5b81590-6814-4d2a-8baa-15c4b6c7f960
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.