ABK is a Windows downloader associated with the China-linked espionage group Tick, also tracked as BRONZE BUTLER. It has been in use since at least 2019 and has been observed as part of multi-stage intrusions in which it is deployed alongside other tooling, including loaders and backdoors. ABK is designed to stage and execute follow-on malware while collecting basic host profiling data to support operator decision-making and defense evasion.
ABK can decrypt AES-encrypted payloads, extract a malicious PE payload concealed within an image, and download additional files from command-and-control infrastructure. It has been observed using HTTP for command-and-control communications and can invoke the Windows command shell to execute a PE on a compromised host. The malware also performs security software discovery by identifying the installed antivirus product on the victim system. For execution and stealth, ABK can inject shellcode into svchost.exe.
Reporting on related intrusion chains indicates ABK has been delivered as an encrypted payload by a loader that decrypts and launches it, after which ABK performs host reconnaissance and retrieves subsequent malware. It has been found on servers and workstations in intrusions affecting organizations in Japan. Its use aligns with long-running Chinese cyber-espionage tradecraft focused on covert access, staged payload delivery, and post-compromise expansion within victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
7 distinct techniques documented for this family, organized by ATT&CK tactic.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE BUTLER threat profile.
Malware capable of injecting shellcode into svchost.exe.
Malware capable of decrypting AES-encrypted payloads.
Malware capable of decrypting AES-encrypted payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.