Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Roaming Tiger

Also known as: BRONZE WOODLAND, Rotten Tomato

Description

**Targets:** GHOST **Toolset/Malware:** "SOGU **Operations:** Roaming Tiger, TOPNEWS **Notes:** TEMPFUN

AI Analysis

· 1 week ago

Executive Summary

Roaming Tiger, also known as BRONZE WOODLAND and Rotten Tomato, is a nation-state threat actor primarily involved in espionage activities. The group has demonstrated advanced capabilities in targeting sensitive networks through campaigns such as Roaming Tiger and TOPNEWS, leveraging tools like SOGU for information gathering and intelligence operations.

Goals & Targeting

Roaming Tiger's strategic objectives focus on espionage-driven goals, likely targeting sectors of interest to the nation backing these operations. While specific targeted sectors and countries remain unclear in the provided data, such actors typically aim for sensitive areas like government Ministries, defense contractors, and critical infrastructure. The group’s victims are often selected based on geopolitical interests and intelligence value.

Enhanced Description

Roaming Tiger is an identified nation-state cyber threat actor with primary motivations centered around espionage. The actor's operational techniques include targeted attacks on governmental and private sector entities to extract sensitive information. Known for campaigns such as Roaming Tiger and TOPNEWS, the group has demonstrated a capability to persist within networks and exfiltrate valuable data using sophisticated tools like SOGU. The actor's activities are linked to broader geopolitical espionage operations, often aimed at gathering strategic intelligence.

Key Capabilities

  • Espionage-focused network intrusions
  • Persistent network presence
  • Information exfiltration using custom tools (e.g., SOGU)
  • Spear-phishing campaigns
  • Lateral movement within targeted networks

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Information Collection

ATT&CK Techniques

T1086 - Powershell
T1054.001 - Remote Access Tools
T1566.003 - OS Credential Dumping: Registry Hive/Local Security Authority (LSA)
T1217 - Email Compromise
T1290 - Exploit Public-Facing Web Servers

Software / Tooling

SOGU
Custom malware toolset

Campaigns & Victims

Roaming Tiger has been involved in multiple campaigns, including TOPNEWS and Roaming Tiger itself, indicating a sustained operational tempo. The actors have demonstrated patience and focus on maintaining long-term access to target networks for intelligence gathering. Past operations suggest a preference for spear-phishing as an initial attack vector, followed by internal network movement.

IOC Patterns

  • Spear phishing emails targeting specific organizations
  • Network traffic consistent with data exfiltration protocols
  • Use of custom malware like SOGU
  • Presence of known APT indicators in targeted systems

Recommended Actions

  • Implement multi-factor authentication for critical accounts.
  • Monitor network traffic for signs of persistent threats.
  • Conduct regular security audits and patch management.
  • Train employees to recognize spear-phishing attempts.
  • Use endpoint detection and response (EDR) tools.

Suggested Tags

Nation-state
APT
Espionage
Intelligence Gathering

Confidence Assessment

The confidence in the data provided is moderate due to gaps in specific details such as targeted sectors, countries, and exact toolset functionality. Known campaign activity and linkedMITRE ATT&CK techniques contribute to a higher confidence level in general behavioral patterns but lack specifics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

2

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-state
Espionage
Intelligence Gathering

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.