Tick, also tracked as BRONZE BUTLER, REDBALDKNIGHT, STALKER PANDA, STALKER TAURUS, SWIRL TYPHOON, and TELLURIUM, is a Chinese threat actor. The content also links Tick to TA428 in reporting around shared tooling and malware use, but only directly supports Tick/BRONZE BUTLER as aliases here. The group has targeted East Asia, including compromise of the web server of an East Asia-based IT services company during ProxyLogon exploitation, and has been associated with activity affecting Mongolian organizations through malware linked to TA428/Tmanger reporting. Observed tradecraft includes spearphishing with malicious Microsoft Word attachments to induce user execution; use of batch scripts and PowerShell for execution; persistence via Registry Run keys added by batch scripts; HTTP command-and-control; downloading encoded payloads and decoding them on victim systems; Base64 encoding of data sent to C2; account discovery using net user /domain; collection of file listings from victims followed by creation of targeted theft lists; exfiltration of stolen local files; and deletion of RAR archives after exfiltration. The group has also disguised malware with the same name as an existing file on a file share server to induce additional user execution and lateral spread, used open-source credential access tools including Mimikatz, gsecdump, and Windows Credential Editor, and incorporated code to terminate antivirus processes. Additional reporting in the content states that the Daserf backdoor used by REDBALDKNIGHT/BRONZE BUTLER employed steganography. ESET also identified Tick as one of multiple Chinese-backed groups exploiting Microsoft Exchange ProxyLogon vulnerabilities and assessed that Tick likely had access to an exploit before patches were released.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
The exploitation of a recently disclosed critical security flaw in Motex Lanscope Endpoint Manager has been attributed to a cyber espionage group known as Tick. The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges... confirmed reports of active abuse of the security defect to drop a backdoor on compromised systems.
...exploited Microsoft vulnerabilities, including CVE-2014-4114...
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
Our latest report into Tick’s activity found it exploiting the ProxyLogon vulnerability to compromise a South Korean IT company, as one of the groups with access to that remote code execution exploit before the vulnerability was publicly disclosed.
6 more CVEs tied to this actor tracked in Mallory.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.