Bronze Butler, Tick, RedBaldNight, Stalker Panda

Description

(SecureWorks) CTU analysis indicates that Bronze Butler primarily targets organizations located in Japan. The threat group has sought unauthorized access to networks of organizations associated with critical infrastructure, heavy industry, manufacturing, and international relations. Secureworks analysts have observed Bronze Bulter exfiltrating the following categories of data:

• Intellectual property related to technology and development • Product specification • Sensitive business and sales-related information • Network and system configuration files • Email messages and meeting minutes

The focus on intellectual property, product details, and corporate information suggests that the group seeks information that they believe might be of value to competing organizations. The diverse targeting suggests that Bronze Bulter may be tasked by multiple teams or organizations with varying priorities.

Names

NameName-Giver
Bronze ButlerSecureWorks
CTG-2006SecureWorks
TickSymantec
TEMP.TickFireEye
RedBaldNightTrend Micro
Stalker PandaCrowdstrike
Stalker TaurusPalo Alto
Swirl TyphoonMicrosoft

Country

State-sponsored, National University of Defense and Technology

Motivation

  • Information theft and espionage

First Seen

2006

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

334d9e0e-dab2-4bc5-8db2-5ab016f36947

Last Card Change

2025-06-28