Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BRONZE BUTLER

Also known as: REDBALDKNIGHT, Tick, BRONZE BUTLER, Nian, STALKER PANDA, G0060, Stalker Taurus, PLA Unit 61419, Swirl Typhoon, TEMP.Tick, TICK CASTLE

Description

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.(Citation: Trend Micro Daserf Nov 2017)(Citation: Secureworks BRONZE BUTLER Oct 2017)(Citation: Trend Micro Tick November 2019)

TTP Summary

ENDTRADE

AI Analysis

· 1 week ago

Executive Summary

BRONZE BUTLER is a suspected Chinese-origin cyber espionage group targeting Japanese organizations since at least 2008. Known for sophisticated campaigns using malware such as ShadowPad and Daserf, the group primarily focuses on stealing sensitive information from government, biotechnology, electronics manufacturing, and industrial chemistry sectors.

Goals & Targeting

BRONZE BUTLER's strategic objectives appear to be centered around intelligence-gathering and espionage against key sectors in Japan. This alignment suggests a focus on obtaining technological and industrial advantages through the compromise of biotechnology, electronics manufacturing, and industrial chemistry industries. The group’s targeting of Japan indicates a potential nation-state interest in gaining strategic insights into Japanese industries and government operations.

Enhanced Description

BRONZE BUTLER is a well-documented cyber espionage threat actor believed to have Chinese origins. The group has been active since at least 2008 and has specifically targeted Japanese organizations across various critical sectors including government, biotechnology, electronics manufacturing, and industrial chemistry. Their primary modus operandi involves the use of custom malware, such as ShadowPad and Daserf, which are designed for persistence, data collection, and lateral movement within compromised networks. BRONZE BUTLER's campaigns often exhibit a high level of sophistication, including the use of steganography, legitimate-looking tools like scheduled tasks and system commands, and sophisticated data exfiltration techniques. The group has been linked to numerous incidents in Japan, with their activities primarily focused on stealing sensitive intellectual property, strategic information, and proprietary data.

Key Capabilities

  • Cyber espionage
  • Custom malware development (ShadowPad, Daserf)
  • Spear-phishing campaigns
  • Lateral movement within networks
  • Data exfiltration via encryption techniques
  • Credential dumping using tools like Avenger

MITRE ATT&CK Tactics

Collection
Exfiltration
Impact
Lateral Movement
Defense Evasion
Discovery

ATT&CK Techniques

T1566.001
T1059.003
T1550.003
T1078.001
T1027.003
T1007
T1036.005
T1548.002
T1105

Software / Tooling

ShadowPad
Daserf
Avenger
down_new
ABK
build_downer
Trend Micro Daserf
BBK

Campaigns & Victims

BRONZE BUTLER is known for the ENDTRADE campaign, which targeted Japanese organizations with tailored spear-phishing emails and malicious software. The group frequently uses legitimate-looking tools and techniques to avoid detection while compromising systems and extracting data. Campaigns often leverage custom malware to establish persistence and facilitate long-term espionage activities. Notable for its focus on Japan's critical sectors, BRONZE BUTLER has demonstrated a consistent operational tempo over the years.

IOC Patterns

  • Spear-phishing emails with malicious attachments (e.g., DOC files containing embedded scripts)
  • Scheduled tasks created by legitimate-looking utilities
  • Malicious processes using legitimate command-line tools
  • Fileless malware leveraging Windows commands and PowerShell
  • Binary padding and obfuscation techniques in malware

Recommended Actions

  • Implement multi-layered email filtering to detect spear-phishing attempts.
  • Enhance endpoint detection and response (EDR) solutions to identify malicious processes like ShadowPad.
  • Monitor network traffic for indicators of exfiltration activities, such as encrypted data transfers or unusual patterns.
  • Conduct regular audits of system accounts and permissions to prevent unauthorized access.
  • Use network segmentation to limit lateral movement within critical networks.

Suggested Tags

espionage
cyber espionage
Japan-focused
electronics manufacturing
biotechnology

Confidence Assessment

The intelligence on BRONZE BUTLER is considered reliable, with multiple sources corroborating their activities and techniques. However, certain details regarding their exact origins and long-term strategic objectives remain speculative. There is high confidence in the group's association with Chinese cyber espionage efforts but limited visibility into recent operations since 2019.

ATT&CK Techniques

Command & Control
5 techniques
Discovery
6 techniques
Execution
8 techniques
Stealth
8 techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Trend Micro Daserf Nov 2017 — Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.
  2. Secureworks BRONZE BUTLER Oct 2017 — Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
  3. Trend Micro Tick November 2019 — Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.
  4. Symantec Tick Apr 2016 — DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

Intel Summary

40

Techniques

17

Tools

1

Campaigns

0

IOCs

0

Observed Data

12

Tactics

Tags

APT
Healthcare Targeting
Critical Infrastructure
Government Targeting
espionage
cyber espionage
Japan-focused
electronics manufacturing
biotechnology

Details

MITRE ID
G0060
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--93f52415-0fe4-4d3d-896c-fc9b8e88ab90
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.