ATT&CKGroupsTonto Team

Tonto Team

G0131

Threat group.View on attack.mitre.org

About this group

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

Techniques used15

Procedure examples15

TechniqueProcedure example
T1003
OS Credential Dumping

Tonto Team has used a variety of credential dumping tools.

T1056.001
Keylogging

Tonto Team has used keylogging tools in their operations.

T1059.001
PowerShell

Tonto Team has used PowerShell to download additional payloads.

T1059.006
Python

Tonto Team has used Python-based tools for execution.

T1068
Exploitation for Privilege Escalation

Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.

T1069.001
Local Groups

Tonto Team has used the ShowLocalGroupDetails command to identify administrator, user, and guest accounts on a compromised host.

T1090.002
External Proxy

Tonto Team has routed their traffic through an external server in order to obfuscate their location.

T1105
Ingress Tool Transfer

Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader.

T1135
Network Share Discovery

Tonto Team has used tools such as NBTscan to enumerate network shares.

T1203
Exploitation for Client Execution

Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads.

T1204.002
Malicious File

Tonto Team has relied on user interaction to open their malicious RTF documents.

T1210
Exploitation of Remote Services

Tonto Team has used EternalBlue exploits for lateral movement.

T1505.003
Web Shell

Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server.

T1566.001
Spearphishing Attachment

Tonto Team has delivered payloads via spearphishing attachments.

T1574.001
DLL

Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL.

Software6

Campaigns0

None recorded.

References6

  1. ARS Technica China Hack SK April 2017 Open source
    Sean Gallagher. (2017, April 21). Researchers claim China trying to hack South Korea missile defense efforts. Retrieved October 17, 2021.
  2. ESET Exchange Mar 2021 Open source
    Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021.
  3. FireEye Chinese Espionage October 2019 Open source
    Nalani Fraser, Kelli Vanderlee. (2019, October 10). Achievement Unlocked - Chinese Cyber Espionage Evolves to Support Higher Level Missions. Retrieved November 17, 2024.
  4. Kaspersky CactusPete Aug 2020 Open source
    Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.
  5. Talos Bisonal 10 Years March 2020 Open source
    Warren Mercer, Paul Rascagneres, Vitor Ventura. (2020, March 6). Bisonal 10 Years of Play. Retrieved October 17, 2021.
  6. Trend Micro HeartBeat Campaign January 2013 Open source
    Roland Dela Paz. (2003, January 3). The HeartBeat APT Campaign. Retrieved October 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.