Tonto Team is a Chinese state-linked cyber espionage threat actor active for years against government, military, diplomatic, telecommunications, critical infrastructure, and private-sector targets, particularly in Asia and especially Northeast Asia. The group is widely tracked under multiple aliases including CactusPete, Karma Panda, Earth Akhlut, Bronze Huntley, Copper Typhoon, SharpR, TAG-74, Tonto, and Tonto Team. Tonto Team is best known for long-running espionage operations using spearphishing and malicious documents to gain initial access, often leveraging decoy themes relevant to government affairs, regional politics, or telecommunications. Public reporting has linked the group to the use of Royal Road-built lure documents and exploitation of Microsoft Office vulnerabilities, as well as delivery of malware families strongly associated with Chinese intrusion activity. The group has been associated with Bisonal and ShadowPad-related activity, and reporting has also connected it to infrastructure or tooling overlaps involving Tmanger and broader Chinese contractor or shared-malware ecosystems. The actor’s targeting has included governments and public-sector entities, critical infrastructure operators, telecommunications organizations, and businesses in countries such as Russia, Pakistan, India, Mongolia, and Vietnam. Tonto Team has also been discussed in connection with activity affecting Indian power-sector organizations, although some campaigns with overlapping infrastructure have been tracked separately due to insufficient evidence for definitive attribution. The group’s victimology and operational focus are consistent with strategic intelligence collection and regional geopolitical interests aligned with Chinese state objectives. Observed tradecraft includes phishing-based delivery, user execution of malicious attachments, exploitation for privilege escalation, PowerShell execution, deployment of web shells, installation of Windows services for persistence, use of shared modules, and network share discovery. The group has been associated with modular backdoors and remote access tooling that support host reconnaissance, command execution, file operations, credential or keylogging-related collection, screen capture, and encrypted command-and-control communications. Reporting also indicates overlap with malware and infrastructure ecosystems used by other Chinese espionage clusters, reflecting the broader pattern of shared tooling, contractors, and commercially supplied implants in PRC-aligned operations. Tonto Team is generally assessed as an espionage-focused actor rather than a financially motivated one. Its operations, malware choices, and regional targeting patterns place it among the better-known Chinese advanced persistent threat groups conducting sustained intelligence collection and strategic access operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
The example documents shown above both exploit CVE-2018-0798, a remote execution vulnerability in Microsoft Office to install the embedded malware.
May 2018: a new wave of targeted attacks abusing CVE-2018-8174 (this exploit has been associated with the DarkHotel APT group, as described on Securelist), with diplomatic, defense, manufacturing, military and government targets in Asia and Eastern Europe;
...has exploited Office vulnerabilities such as CVE-2017-11882...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.
9 more CVEs tied to this actor tracked in Mallory.
98 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Suspected PLA-linked unit identified as a recipient of the commercially sold ShadowPad backdoor.
Named threat actor referenced in retrospective threat reporting.
Referenced in the detection annotations as a threat actor associated with exploitation for privilege escalation activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.