Tonto Team is a China-linked APT group known for cyber espionage targeting military and government entities.
Analyst brief
Tonto Team is a Chinese nation-state APT group active since at least 2013. It primarily targets military, government, and private sector entities in Eastern Europe, the US, Japan, South Korea, and Taiwan. They gain initial access via Spearphishing Attachments and deploy Bisonal RAT, ShadowPad, and Web Shells, using tools like Mimikatz and LaZagne for OS Credential Dumping and Keylogging. Defenders should focus on detecting malicious email attachments, unauthorized Python script execution, Network Share Discovery, and C2 communications via External Proxies.
Tonto Team
CactusPeteKARMA PANDABRONZE HUNTLEY
nation-state
Tonto Team is a Chinese-speaking APT group that has been active since at least 2013. They primarily target military, diplomatic, and infrastructure organizations in Asia and Eastern Europe. The group has been observed using various malware, including the Bisonal RAT and ShadowPad. They employ spear-phishing emails with malicious attachments as their preferred method of distribution.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)