Threat group.View on attack.mitre.org
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping. |
| T1005 Data from Local System |
BRONZE BUTLER has exfiltrated files stolen from local systems. |
| T1007 System Service Discovery |
BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| T1018 Remote System Discovery |
BRONZE BUTLER typically use |
| T1027.001 Binary Padding |
BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection. |
| T1027.003 Steganography |
BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| T1036 Masquerading |
BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF. |
| T1036.002 Right-to-Left Override |
BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware. |
| T1036.005 Match Legitimate Resource Name or Location |
BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems. |
| T1039 Data from Network Shared Drive |
BRONZE BUTLER has exfiltrated files stolen from file shares. |
| T1053.002 At |
BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement. |
| T1053.005 Scheduled Task |
BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement. |
| T1059.001 PowerShell |
BRONZE BUTLER has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
BRONZE BUTLER has used batch scripts and the command-line interface for execution. |
| T1059.005 Visual Basic |
BRONZE BUTLER has used VBS and VBE scripts for execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.