BRONZE BUTLER
BRONZE BUTLER is a Chinese threat actor also tracked as Tick, RedBaldKnight, Stalker Panda, Stalker Taurus, Swirl Typhoon, and Tellurium. The content links the group to Chinese activity and notes CTU reporting that ShadowPad activity associated with BRONZE BUTLER was reportedly linked to the PLA Northern Theater Command. The group has targeted organizations in East Asia and was observed compromising the web server of an East Asia-based IT services company during ProxyLogon exploitation; CTU reporting also links BRONZE BUTLER-associated ShadowPad activity to targeting in South Korea, Russia, Japan, and Mongolia. Observed tradecraft in the provided content includes spearphishing emails with malicious Microsoft Word attachments for initial access; execution via batch scripts, the Windows command-line interface, and PowerShell; persistence via Registry Run keys added by batch scripts; and use of schtasks to register scheduled tasks during lateral movement. BRONZE BUTLER has used HTTP for command and control, with several tools Base64-encoding data when posting to C2 servers, and has downloaded encoded payloads that are decoded on victim systems. The group has exfiltrated files from local systems, deleted RAR archives after exfiltration, and has masqueraded malware by giving it the same name as an existing file on a file share server to induce users to launch it. The content also states that BRONZE BUTLER incorporated code into several tools to terminate antivirus processes and used open-source credential theft and dumping tools including Mimikatz, gsecdump, and Windows Credential Editor. A referenced 2017 report states that the Daserf backdoor used by REDBALDKNIGHT/BRONZE BUTLER employed steganography. The content also states that Tick was among the Chinese-backed groups exploiting Microsoft Exchange ProxyLogon vulnerabilities, and ESET assessed that Tick likely had access to an exploit before patches were released.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Military
- Government & Administration
- Software & Services
Where they target
Geographies tied to known operations.
- 🇰🇷 South Korea
- 🇯🇵 Japan
Tradecraft
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
Associated vulnerabilities
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
The exploitation of a recently disclosed critical security flaw in Motex Lanscope Endpoint Manager has been attributed to a cyber espionage group known as Tick. The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges... confirmed reports of active abuse of the security defect to drop a backdoor on compromised systems.
...exploited Microsoft vulnerabilities, including CVE-2014-4114...
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
Our latest report into Tick’s activity found it exploiting the ProxyLogon vulnerability to compromise a South Korean IT company, as one of the groups with access to that remote code execution exploit before the vulnerability was publicly disclosed.
6 more CVEs tied to this actor tracked in Mallory.
Observables
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed as a threat actor associated with use of Cobalt Strike PowerShell loader patterns.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.