THREAT_ACTOR · G0060
BRONZE BUTLER
Also known as: BRONZE BUTLER, REDBALDKNIGHT, Tick
Profile
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.
MITRE ATT&CK ↗Techniques
40 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1005 Data from Local SystemT1007 System Service DiscoveryT1018 Remote System DiscoveryT1027.001 Binary PaddingT1027.003 SteganographyT1036 MasqueradingT1036.002 Right-to-Left OverrideT1036.005 Match Legitimate Resource Name or LocationT1039 Data from Network Shared DriveT1053.002 AtT1053.005 Scheduled TaskT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.006 PythonT1070.004 File DeletionT1071.001 Web ProtocolsT1080 Taint Shared ContentT1083 File and Directory DiscoveryT1087.002 Domain AccountT1102.001 Dead Drop ResolverT1105 Ingress Tool TransferT1113 Screen CaptureT1124 System Time DiscoveryT1132.001 Standard EncodingT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1518 Software DiscoveryT1547.001 Registry Run Keys / Startup FolderT1548.002 Bypass User Account ControlT1550.003 Pass the TicketT1560.001 Archive via UtilityT1566.001 Spearphishing AttachmentT1573.001 Symmetric CryptographyT1574.001 DLLT1588.002 ToolT1685 Disable or Modify Tools
Software
14 malware/tools attributed to this actor.
MimikatzWindows Credential EditorgsecdumpNetcmdatschtasksDaserfABKBBKbuild_downerdown_newAvengerShadowPad
Related corpus activity
10,209 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to BRONZE BUTLER.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,209.