Tonto Team is a Chinese state-sponsored cyberespionage actor active since at least 2009. It is also known as CactusPete, Bronze Huntley, Copper Typhoon, Earth Akhlut, Karma Panda, HeartBeat, Sharp R, TAG-74, and Team Tonto. Its targets include government, military, energy, financial, educational, healthcare, and technology organizations. Early operations focused on South Korea, Japan, Taiwan, and the United States, with activity expanding into Eastern Europe by 2020. Its targeting includes cybersecurity companies and software-development organizations. The group uses spearphishing attachments, organizational impersonation, and malicious RTF documents generated with the Royal Road exploit builder. Its malware includes Bisonal and Bisonal.DoubleT, Bisonal.Dropper, ShadowPad, and the QuickMute downloader, also known as TontoTeam.Downloader. These tools support host discovery, remote command execution, process management, payload delivery, and command-and-control communications. Observed deployments use registry-based persistence, encrypted or obfuscated payloads and communications, and in-memory loading of additional components. Tonto Team has exploited CVE-2019-0803 and the Windows vulnerability addressed by MS16-032 for privilege escalation, and EternalBlue for lateral movement. In March 2021, it exploited Microsoft Exchange ProxyLogon vulnerabilities to compromise email servers at Eastern European procurement and cybersecurity-consulting companies, deploying ShadowPad and Bisonal. It also conducted unsuccessful spearphishing attacks against Group-IB employees in 2021 and 2022. Tonto Team has shared infrastructure and tooling with Tick; use of shared tools such as ShadowPad and Royal Road is not independently sufficient for attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.
In 2020, they exploited CVE-2019-9489 and CVE-2020-8468 in Trend Micro’s security solutions that were exposed to the Internet, in order to deliver ShadowPad into internal networks for further exploitation.
10 more CVEs tied to this actor tracked in Mallory.
433 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese state-sponsored espionage group mentioned as historical background for its use of RoyalRoad to create a weaponized RTF document targeting Group-IB employees. The article does not attribute the G7-targeting campaign to Tonto or any other specific named group.
Listed as Tonto Team in the detection's technique annotations; the content does not attribute ShieldCrash exploitation to this group.
Listed as an annotation to a renamed-Python-binary detection; no actor-specific campaign or behavior is described.
Listed in the detection annotation metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.