Bronze Highland

Description

(SecureWorks) BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Third party reporting suggests the threat group also targets India, Malaysia and Taiwan and leverages Cobalt Strike and KsRemote Android Rat. CTU researchers assess with moderate confidence that BRONZE HIGHLAND operates on behalf of China and has a remit covering espionage against domestic human rights and pro-democracy advocates and nations neighbouring China.

Names

NameName-Giver
Bronze HighlandSecureWorks
Evasive PandaMalwarebytes
DaggerflySymantec
Storm CloudVolexity
StormBambooVolexity
TAG-102Recorded Future
TAG-112Recorded Future
Digging TaurusPalo Alto

Country

State-sponsored

Motivation

  • Information theft and espionage

First Seen

2012

Observed Sectors

Observed Countries

Tools

Operations

Information

Other Information

Uuid

8c9d0ce1-0e92-4de2-b8e0-053b16ad37ed

Last Card Change

2025-06-27