Also known as: UNC302
BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense, engineering, pharmaceutical and technology companies. The threat group typically uses scan-and-exploit for initial access, deploys the China Chopper webshell for remote execution and persistence, and creates RAR archives with a '.jpg' file extension for data exfiltration. In July 2020 the U.S. Department of Justice indicted two Chinese hackers CTU researchers assess are members of the BRONZE SPRING threat group. The Department of Justice allege these hackers were responsible for compromising networks of hundreds of organisations and individuals in the U.S. and abroad since 2009, and that exfiltrated data would be passed to the Chinese Ministry of State Security or sold for financial gain.
Targeted Sectors
Executive Summary
BRONZE SPRING, assessed with high confidence to be China-linked, conducts state-sponsored and financially motivated cyber espionage targeting defense, technology, and pharmaceutical sectors to steal intellectual property. The group employs scan-and-exploit attacks, deploys the China Chopper webshell, and exfiltrates data via stealthy RAR archives disguised as .jpg files. U.S. DOJ indictment of two members in 2020 highlights the group's long-term operations since 2009.
Goals & Targeting
BRONZE SPRING's primary objective is the systematic theft of intellectual property from sectors critical to national security and economic dominance, such as defense, technology, and pharmaceuticals. Targeting these sectors provides access to cutting-edge research, proprietary engineering data, and sensitive commercial innovations. The group's operations suggest dual motivations: state-sponsored espionage to bolster China's technological capabilities and financial gain through the sale of stolen data. Victims are often multinational corporations and academic institutions in countries with high concentrations of advanced R&D, including the U.S., Japan, and South Korea.
Enhanced Description
BRONZE SPRING, also known as UNC302, is a sophisticated threat group linked to China's state intelligence apparatus. CTU researchers attribute the group's activities to the theft of intellectual property from defense, engineering, pharmaceutical, and technology companies, with stolen data allegedly shared with the Chinese Ministry of State Security or sold for financial gain. The group's modus operandi involves initial access through scan-and-exploit attacks on vulnerable web applications, followed by the deployment of the China Chopper webshell to maintain persistence and execute commands remotely. Data exfiltration is achieved by compressing stolen information into RAR archives and renaming them with .jpg file extensions to evade detection. The U.S. Department of Justice's 2020 indictment of two hackers affiliated with BRONZE SPRING underscores the group's operational maturity and sustained campaign spanning over a decade, impacting hundreds of organizations globally. This activity reflects a strategic focus on economic and technological espionage to advance China's competitive interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BRONZE SPRING's campaigns exhibit a high operational tempo, with sustained activity since at least 2009 and ongoing operations targeting a broad range of industries. The group's reliance on scan-and-exploit and webshell-based persistence indicates a focus on exploiting unpatched vulnerabilities rather than zero-day exploits. Campaigns often involve multi-stage payloads and the use of compromised infrastructure for command-and-control channels. Notably, the 2020 DOJ indictment reveals the group's long-term coordination with Chinese state entities, suggesting state sponsorship and strategic alignment with national objectives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence is assigned to BRONZE SPRING's attribution to China due to the U.S. DOJ indictment and consistent TTPs aligned with state-sponsored espionage. However, gaps exist in precise first/last seen timestamps, detailed malware tooling, and direct linkage to specific Chinese government entities beyond the Ministry of State Security. Additional analysis of IOC samples and network traffic patterns could further solidify confidence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics