Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BRONZE SPRING

Also known as: UNC302

Description

BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense, engineering, pharmaceutical and technology companies. The threat group typically uses scan-and-exploit for initial access, deploys the China Chopper webshell for remote execution and persistence, and creates RAR archives with a '.jpg' file extension for data exfiltration. In July 2020 the U.S. Department of Justice indicted two Chinese hackers CTU researchers assess are members of the BRONZE SPRING threat group. The Department of Justice allege these hackers were responsible for compromising networks of hundreds of organisations and individuals in the U.S. and abroad since 2009, and that exfiltrated data would be passed to the Chinese Ministry of State Security or sold for financial gain.

Goals & Targeting

Targeted Sectors

Information technology
Education
Gaming
Energy
Pharmaceutical
Defense

AI Analysis

· 1 week ago

Executive Summary

BRONZE SPRING, assessed with high confidence to be China-linked, conducts state-sponsored and financially motivated cyber espionage targeting defense, technology, and pharmaceutical sectors to steal intellectual property. The group employs scan-and-exploit attacks, deploys the China Chopper webshell, and exfiltrates data via stealthy RAR archives disguised as .jpg files. U.S. DOJ indictment of two members in 2020 highlights the group's long-term operations since 2009.

Goals & Targeting

BRONZE SPRING's primary objective is the systematic theft of intellectual property from sectors critical to national security and economic dominance, such as defense, technology, and pharmaceuticals. Targeting these sectors provides access to cutting-edge research, proprietary engineering data, and sensitive commercial innovations. The group's operations suggest dual motivations: state-sponsored espionage to bolster China's technological capabilities and financial gain through the sale of stolen data. Victims are often multinational corporations and academic institutions in countries with high concentrations of advanced R&D, including the U.S., Japan, and South Korea.

Enhanced Description

BRONZE SPRING, also known as UNC302, is a sophisticated threat group linked to China's state intelligence apparatus. CTU researchers attribute the group's activities to the theft of intellectual property from defense, engineering, pharmaceutical, and technology companies, with stolen data allegedly shared with the Chinese Ministry of State Security or sold for financial gain. The group's modus operandi involves initial access through scan-and-exploit attacks on vulnerable web applications, followed by the deployment of the China Chopper webshell to maintain persistence and execute commands remotely. Data exfiltration is achieved by compressing stolen information into RAR archives and renaming them with .jpg file extensions to evade detection. The U.S. Department of Justice's 2020 indictment of two hackers affiliated with BRONZE SPRING underscores the group's operational maturity and sustained campaign spanning over a decade, impacting hundreds of organizations globally. This activity reflects a strategic focus on economic and technological espionage to advance China's competitive interests.

Key Capabilities

  • Scan-and-exploit attacks targeting vulnerable web applications
  • Deployment of the China Chopper webshell for remote code execution and persistence
  • Data exfiltration via RAR archives with misleading .jpg file extensions
  • Long-term network infiltration and lateral movement techniques
  • Evasion of detection through obfuscation of malicious files

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration
Discovery

ATT&CK Techniques

T1102.001 - Exploit Public-Facing Application
T1059.003 - Remote Access Tool: Web Shell
T1040.001 - Exfiltration via Archive
T1114 - Query Registry
T1025 - Kernel Driver
T1560.001 - Archive Collected Data

Software / Tooling

China Chopper webshell
RAR compression utility with .jpg file obfuscation

Campaigns & Victims

BRONZE SPRING's campaigns exhibit a high operational tempo, with sustained activity since at least 2009 and ongoing operations targeting a broad range of industries. The group's reliance on scan-and-exploit and webshell-based persistence indicates a focus on exploiting unpatched vulnerabilities rather than zero-day exploits. Campaigns often involve multi-stage payloads and the use of compromised infrastructure for command-and-control channels. Notably, the 2020 DOJ indictment reveals the group's long-term coordination with Chinese state entities, suggesting state sponsorship and strategic alignment with national objectives.

IOC Patterns

  • Scan-and-exploit of unpatched web servers
  • China Chopper webshell deployment via HTTP/HTTPS
  • RAR archives with .jpg file extensions containing exfiltrated data
  • Use of compromised hosting services for C2 infrastructure

Recommended Actions

  • Implement continuous vulnerability scanning and patch management for web-facing assets
  • Deploy advanced threat detection solutions to identify China Chopper webshell activity
  • Monitor for unusual file types (e.g., .jpg files with RAR content) in data exfiltration channels
  • Enforce strict network segmentation to limit lateral movement post-compromise
  • Conduct employee training on social engineering and phishing countermeasures

Suggested Tags

APT
espionage
IP-theft
China-linked
defense-sector
technology-sector
pharmaceutical-sector

Confidence Assessment

High confidence is assigned to BRONZE SPRING's attribution to China due to the U.S. DOJ indictment and consistent TTPs aligned with state-sponsored espionage. However, gaps exist in precise first/last seen timestamps, detailed malware tooling, and direct linkage to specific Chinese government entities beyond the Ministry of State Security. Additional analysis of IOC samples and network traffic patterns could further solidify confidence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
Backdoor / C2
Data Exfiltration
Government Targeting
APT
espionage
IP-theft
China-linked
defense-sector
technology-sector
pharmaceutical-sector

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.