ATT&CKGroupsBRONZE BUTLER

BRONZE BUTLER

G0060

Threat group.View on attack.mitre.org

About this group

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.

Techniques used40

Procedure examples40

TechniqueProcedure example
T1003.001
LSASS Memory

BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping.

T1005
Data from Local System

BRONZE BUTLER has exfiltrated files stolen from local systems.

T1007
System Service Discovery

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

T1018
Remote System Discovery

BRONZE BUTLER typically use ping and Net to enumerate systems.

T1027.001
Binary Padding

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

T1027.003
Steganography

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

T1036
Masquerading

BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF.

T1036.002
Right-to-Left Override

BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware.

T1036.005
Match Legitimate Resource Name or Location

BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.

T1039
Data from Network Shared Drive

BRONZE BUTLER has exfiltrated files stolen from file shares.

T1053.002
At

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.

T1053.005
Scheduled Task

BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement.

T1059.001
PowerShell

BRONZE BUTLER has used PowerShell for execution.

T1059.003
Windows Command Shell

BRONZE BUTLER has used batch scripts and the command-line interface for execution.

T1059.005
Visual Basic

BRONZE BUTLER has used VBS and VBE scripts for execution.

View all 40 procedure examples

Software14

Campaigns0

None recorded.

References3

  1. Secureworks BRONZE BUTLER Oct 2017 Open source
    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
  2. Trend Micro Daserf Nov 2017 Open source
    Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.
  3. Trend Micro Tick November 2019 Open source
    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.