Tick Group is a China-linked cyber-espionage threat actor associated with long-running intelligence collection operations in East Asia. It is widely tracked under aliases including BRONZE BUTLER, Stalker Panda, and Stalker Taurus, and has been linked in public reporting to Chinese military intelligence and PLASSF-aligned activity. The group has historically targeted organizations in Japan, South Korea, and Russia, with emphasis on government, political, and academic entities and related strategic intelligence objectives. Tick Group is known for using spearphishing for initial access, including delivery of compiled HTML help files that trigger execution chains involving DLL search order hijacking. The group has used customized VBScript backdoors derived from ReVBShell and has also been associated with Bisonal, a long-running Chinese backdoor used for follow-on post-compromise operations. Observed functionality includes command execution, host enumeration via WMI and WMIC, persistence through registry autorun mechanisms, and exfiltration over command-and-control channels. The actor has also demonstrated defense-evasion measures, including execution guardrails tied to security product detection, and has relied on spoofed themes and infrastructure intended to blend with regional targets. Overall, Tick Group is best characterized as a Chinese state-aligned espionage operator focused on persistent access and intelligence collection against government-adjacent and strategic targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tick Group is exploiting Lanscope zero-day vulnerabilities to hijack corporate systems, likely for espionage or data theft.
Closely aligned China-linked espionage group referenced as sharing a customized ReVBShell variant with TAG-74 and having documented collaboration and shared capabilities in prior public reporting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.