Tick is a Chinese cyber espionage group known for long-term targeting of critical sectors.
Analyst brief
Tick (also known as BRONZE BUTLER, STALKER PANDA) is a Chinese-origin cyber espionage group active since at least 2008. The group primarily targets critical infrastructure, industrial, manufacturing, diplomacy, media, and engineering sectors in Japan, South Korea, Russia, and China. For initial access, they rely on spearphishing attachments, followed by credential dumping from LSASS memory using tools like Mimikatz and gsecdump, execution of Python and Visual Basic scripts, and maintaining stealth through file deletion and deobfuscation techniques. Defenders should focus on detecting spearphishing campaigns, monitoring for abnormal registry modifications, UAC bypass attempts, and lateral movement activities via Tainted Shared Content.
Tick
NianBRONZE BUTLERREDBALDKNIGHT
nation-state
Tick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese National University of Defense and Technology, which is possibly linked to the PLA. This threat actor targets organizations in the critical infrastructure, heavy industry, manufacturing, and international relations sectors for espionage purposes. The attacks appear to be centered on political, media, and engineering sectors. STALKER PANDA has been observed conducting targeted attacks against Japan, Taiwan, Hong Kong, and the United States.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)