Also known as: REDBALDKNIGHT, Tick, BRONZE BUTLER, Nian, STALKER PANDA, G0060, Stalker Taurus, PLA Unit 61419, Swirl Typhoon, TEMP.Tick, TICK CASTLE
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.(Citation: Trend Micro Daserf Nov 2017)(Citation: Secureworks BRONZE BUTLER Oct 2017)(Citation: Trend Micro Tick November 2019)
ENDTRADE
Executive Summary
BRONZE BUTLER is a suspected Chinese-origin cyber espionage group targeting Japanese organizations since at least 2008. Known for sophisticated campaigns using malware such as ShadowPad and Daserf, the group primarily focuses on stealing sensitive information from government, biotechnology, electronics manufacturing, and industrial chemistry sectors.
Goals & Targeting
BRONZE BUTLER's strategic objectives appear to be centered around intelligence-gathering and espionage against key sectors in Japan. This alignment suggests a focus on obtaining technological and industrial advantages through the compromise of biotechnology, electronics manufacturing, and industrial chemistry industries. The group’s targeting of Japan indicates a potential nation-state interest in gaining strategic insights into Japanese industries and government operations.
Enhanced Description
BRONZE BUTLER is a well-documented cyber espionage threat actor believed to have Chinese origins. The group has been active since at least 2008 and has specifically targeted Japanese organizations across various critical sectors including government, biotechnology, electronics manufacturing, and industrial chemistry. Their primary modus operandi involves the use of custom malware, such as ShadowPad and Daserf, which are designed for persistence, data collection, and lateral movement within compromised networks. BRONZE BUTLER's campaigns often exhibit a high level of sophistication, including the use of steganography, legitimate-looking tools like scheduled tasks and system commands, and sophisticated data exfiltration techniques. The group has been linked to numerous incidents in Japan, with their activities primarily focused on stealing sensitive intellectual property, strategic information, and proprietary data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BRONZE BUTLER is known for the ENDTRADE campaign, which targeted Japanese organizations with tailored spear-phishing emails and malicious software. The group frequently uses legitimate-looking tools and techniques to avoid detection while compromising systems and extracting data. Campaigns often leverage custom malware to establish persistence and facilitate long-term espionage activities. Notable for its focus on Japan's critical sectors, BRONZE BUTLER has demonstrated a consistent operational tempo over the years.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence on BRONZE BUTLER is considered reliable, with multiple sources corroborating their activities and techniques. However, certain details regarding their exact origins and long-term strategic objectives remain speculative. There is high confidence in the group's association with Chinese cyber espionage efforts but limited visibility into recent operations since 2019.
ENDTRADE
No observed data linked yet.
No IOCs linked yet.
40
Techniques
17
Tools
1
Campaigns
0
IOCs
0
Observed Data
12
Tactics