TeamTNTO, also tracked as Team Tonto, is a Chinese-speaking espionage threat cluster associated with the broader Winnti/ShadowPad ecosystem. Reporting has linked the cluster to Chinese contractor and state-aligned intrusion activity, including overlaps with tooling and operations connected to I-Soon and other Chinese nexus groups. The actor has been observed using ShadowPad and related malware families as part of long-running cyber espionage operations. TeamTNTO primarily targets organizations of intelligence interest, including government, military, telecommunications, universities, and non-governmental entities. The group’s operations are consistent with espionage-focused collection rather than financially motivated crime. Tradecraft associated with the cluster includes phishing-based initial access, credential theft, keylogging, persistent remote access, command execution, file collection, screen capture, and data exfiltration. Reporting also indicates use of post-compromise collection platforms designed to ingest and operationalize stolen email and document data, as well as token- or credential-based access to cloud and email accounts for continuous collection. The cluster has been linked through shared tooling and infrastructure patterns to activity also tracked under adjacent Chinese intrusion reporting, including Fishmonger and Earth Lusca, though these are distinct tracking names rather than confirmed synonyms. TeamTNTO is best understood as part of the Chinese state-aligned espionage ecosystem that combines contractor support, commodityized implants within the Winnti/ShadowPad lineage, and operational targeting of public-sector and strategic organizations across multiple regions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.