Datper is a Windows backdoor associated with the China-linked espionage group TICK, also tracked as BRONZE BUTLER. It has been observed in long-running intrusion activity targeting Japanese organizations and featured in later TICK operations against defense, aerospace, chemical, and satellite-sector entities with business ties between Japan and China. Datper appears in TICK’s broader malware ecosystem alongside tools such as Wali, xxmm, down_new, Casper, and ShadowPad.
Observed use places Datper in targeted espionage operations rather than broad criminal distribution. Prior to March 2018, attackers used Wali and a small downloader to spread xxmm and Datper in campaigns exploiting Japanese enterprise software. In Operation ENDTRADE-era activity, Datper variants were deployed as part of spear-phishing-led compromises that relied on stolen legitimate email accounts and Japanese-language lures. Multiple Datper variants were observed from late 2017 onward.
Datper functions as a backdoor that retrieves information from infected hosts and supports post-compromise access for the operator. Reported variant evolution includes adjusted mutex usage and changes to cryptographic implementation, including a modified RC4 initialization, as well as new parameters intended to reduce signature-based antivirus detection. Its development pattern is consistent with TICK’s emphasis on iterative malware refinement, defense evasion, and sustained access in high-value enterprise environments.
Datper has been linked to campaigns focused on Japanese government and private-sector targets, especially organizations holding military, industrial, or proprietary information. Its operational context indicates use in espionage intrusions aimed at intelligence collection and follow-on access within victim networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SKYSEA Client View is a popular piece of asset management software in Japan. The software had a vulnerability (CVE-2016-7836) that allowed remote code execution due to a flaw in processing authentication on the TCP connection with the management console program. | Before March 2018, the attackers used to leverage Wali and the small downloader in order to spread xxmm and Datper.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Emdivi is a bot that communicates via HTTP protocol... Agtid is a bot that communicates via HTTP protocol.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE BUTLER threat profile.
A TICK-associated backdoor variant updated with adjusted mutex objects and new parameters intended to evade antivirus pattern detection while retrieving victim machine information.
Datper is a backdoor/bot used as a secondary payload in BRONZE BUTLER/Tick operations following SKYSEA exploitation, sharing similar PHP C&C panel traits with xxmm.
Mentioned as later observed variants in the same activity context, with modified RC4 initialization, suggesting evolution or related tooling after xxmm activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.