Tonto Team
Tonto Team is a Chinese cyber-espionage threat actor also known as CactusPete, Earth Akhlut, Karma Panda, BRONZE HUNTLEY, Copper Typhoon, SharpR, TAG-74, and Bronze Huntley. Public reporting in the provided content states the group has been known since at least 2013 and has been reported on for nearly ten years. The content describes Tonto Team as a Chinese-speaking, China-linked, and Chinese state-sponsored espionage group, with one report assessing a possible link to the actor with medium confidence and another noting researchers connected the group to China. Based on the provided content, Tonto Team has targeted governments, critical infrastructure, and private businesses globally, especially in Northeast Asia. Reported victim geography and sectors include South Korea, Russia, Japan, Mongolia, Eastern Europe, and telecommunications organizations in Pakistan. Specific incidents in the content include compromise of the email servers of a procurement company and a software development and cybersecurity consulting company in Eastern Europe, and exploitation activity against Microsoft Exchange servers during ProxyLogon-related operations. The group’s tradecraft in the provided material includes spearphishing attachments, malicious Office and RTF documents, and reliance on user interaction to open weaponized files. The content explicitly states that Tonto Team has delivered payloads via spearphishing attachments, relied on user interaction to open malicious RTF documents, and used PowerShell to download additional payloads. The content also associates the group with exploitation for privilege escalation in ATT&CK-aligned annotations. Malware and tooling linked in the content include Bisonal and ShadowPad. Bisonal is described as part of the Tonto Team arsenal and as a remote access trojan associated with Chinese threat actors. ShadowPad is described as a privately developed backdoor sold to multiple suspected PLA units including Tonto Team, and also shared among multiple Chinese threat actors. The content further notes CTU researchers linked ShadowPad activity to BRONZE HUNTLEY, reportedly located in the PLA Northern Theater Command, and that ShadowPad activity associated with this cluster targeted South Korea, Russia, Japan, and Mongolia.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
Associated vulnerabilities
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
The example documents shown above both exploit CVE-2018-0798, a remote execution vulnerability in Microsoft Office to install the embedded malware.
May 2018: a new wave of targeted attacks abusing CVE-2018-8174 (this exploit has been associated with the DarkHotel APT group, as described on Securelist), with diplomatic, defense, manufacturing, military and government targets in Asia and Eastern Europe;
...has exploited Office vulnerabilities such as CVE-2017-11882...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.
9 more CVEs tied to this actor tracked in Mallory.
Observables
98 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected PLA-linked unit identified as a recipient of the commercially sold ShadowPad backdoor.
Listed as a threat actor associated with exploitation for privilege escalation in the context of this Linux malformed authentication entry detection.
Listed in the detection annotations as a threat actor associated with exploitation for privilege escalation.
Listed as a threat actor associated with this detection for suspicious bursts of password changes consistent with automated credential manipulation and privilege escalation activity.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.