Tonto Team
MISPNation-state
CN
Unknown
[Tonto Team](https://attack.mitre.org/groups/G0131) is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. [Tonto Team](https://attack.mitre.org/groups/G0131) has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).(Citation: Kaspersky CactusPete Aug 2020)(Citation: ESET Exchange Mar 2021)(Citation: FireEye Chinese Espionage October 2019)(Citation: ARS Technica China Hack SK April 2017)(Citation: Trend Micro HeartBeat Campaign January 2013)(Citation: Talos Bisonal 10 Years March 2020)
Techniques Used (15)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1003 | OS Credential Dumping | - |
| T1056.001 | Keylogging | - |
| T1059.001 | PowerShell | - |
| T1059.006 | Python | - |
| T1068 | Exploitation for Privilege Escalation | - |
| T1069.001 | Local Groups | - |
| T1090.002 | External Proxy | - |
| T1105 | Ingress Tool Transfer | - |
| T1135 | Network Share Discovery | - |
| T1203 | Exploitation for Client Execution | - |
| T1204.002 | Malicious File | - |
| T1210 | Exploitation of Remote Services | - |
| T1505.003 | Web Shell | - |
| T1566.001 | Spearphishing Attachment | - |
| T1574.001 | DLL | - |
References (10)
- arstechnica.com - Researchers Claim China Trying To Hack South Korea Missile Defense Efforts
- docs.huihoo.com - Anf T07b The Art Of Attribution Identifying And Pursuing Your Cyber Adversaries Final.pdf
- securelist.com - 97962
- wsj.com - Chinas Secret Weapon In South Korea Missile Fight Hackers 1492766403
- pwc.co.uk - Pwc Cyber Threats 2020 A Year In Retrospect.pdf
- fireeye.com - Cds19 Executive S08 Achievement Unlocked.pdf
- welivesecurity.com - Exchange Servers Under Siege 10 Apt Groups
- trendmicro.com - Supply Chain Attack Targeting Pakistani Government Delivers Shad
- sentinelone.com - Targets Of Interest Russian Organizations Increasingly Under Attack By Chinese Apts
- go.recordedfuture.com - Cta 2023 0919.pdf
Aliases (1343)
Related Malware (6)
Metadata
| ID: | 120 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |