Introduction
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017). Kaspersky CactusPete Aug 2020 ESET Exchange Mar 2021 FireEye Chinese Espionage October 2019 ARS Technica China Hack SK April 2017 Trend Micro HeartBeat Campaign January 2013 Talos Bisonal 10 Years March 2020
Activities and Tactics
Targeted Sectors: Military, Government, Private sector
Country of Origin: π¨π³ China
Risk Level: High
Suspected Victims: Eastern Europe, Japan, South Korea, Taiwan, United States
Notable Campaigns
- Seven Pointed Dagger
Tactics, Techniques, and Procedures (TTPs)
- T1135 Network Share Discovery
- T1574.001 DLL
- T1090.002 External Proxy
- T1059.006 Python
- T1069.001 Local Groups
- T1056.001 Keylogging
- T1003 OS Credential Dumping
- T1505.003 Web Shell
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1566.001 Spearphishing Attachment
- T1210 Exploitation of Remote Services
- T1059.001 PowerShell
- T1068 Exploitation for Privilege Escalation
- T1105 Ingress Tool Transfer
ATT&CK technique IDs (denormalized)
- T1003
- T1056.001
- T1059.001
- T1059.006
- T1068
- T1069.001
- T1090.002
- T1105
- T1135
- T1203
- T1204.002
- T1210
- T1505.003
- T1566.001
- T1574.001
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- RoyalRoad RTF Weaponizer:
MITRE ATT&CK Software
- Mimikatz (S0002) β tool
- Bisonal (S0268) β malware
- ShadowPad (S0596) β malware
- LaZagne (S0349) β tool
- NBTscan (S0590) β tool
- gsecdump (S0008) β tool
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [7] TrendMicro Tonto Team October 2020 Daniel Lughi, Jaromir Horejsi. (2020, October 2). Tonto Team - Exploring the TTPs of an advanced threat actor operating a large infrastructure. Retrieved October 17, 2021. [8] CrowdStrike Manufacturing Threat July 2020 Falcon OverWatch Team. (2020, July 14). Manufacturing Industry in the Adversariesβ Crosshairs. Retrieved October 17, 2021. [9] ESET Exchange Mar 2021 Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021. [10] Talos Bisonal Mar 2020 Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022. [11] FireEye Chinese Espionage October 2019 Nalani Fraser, Kelli Vanderlee. (2019, October 10). Achievement Unlocked - Chinese Cyber Espionage Evolves to Support Higher Level Missions. Retrieved November 17, 2024. [12] Trend Micro HeartBeat Campaign January 2013 Roland Dela Paz. (2003, January 3). The HeartBeat APT Campaign. Retrieved October 17, 2021. [13] ARS Technica China Hack SK April 2017 Sean Gallagher. (2017, April 21). Researchers claim China trying to hack South Korea missile defense efforts. Retrieved October 17, 2021. [14] Secureworks BRONZE HUNTLEY Secureworks. (2021, January 1). BRONZE HUNTLEY Threat Profile. Retrieved May 5, 2021. [15] Kaspersky CactusPete Aug 2020 Zykov, K. (2020, August 13). CactusPete APT groupβs updated Bisonal backdoor. Retrieved May 5, 2021. [11] Trend Micro HeartBeat Campaign January 2013