>samit_hota
Back to adversary profiles

Threat Actor Dossier

Tonto Team (G0131): A Decade of Chinese Cyber Espionage

G0131

Also tracked as Earth Akhlut · BRONZE HUNTLEY · CactusPete · Karma Panda · 12 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
China
Motivation
Espionage · Intellectual Property Theft
Samit Hota·
Target Sectors
Government, Military, Defense, Energy, Mining, Financial, Education, Healthcare, Technology, Media, Telecommunications, IT & ITES
Associated Malware
Bisonal, Dexbia, ShadowPad, TontoTeam.Downloader (QuickMute), Royal Road RTF Weaponizer, Mimikatz, LaZagne, NBTscan
#threat-actor#g0131

Overview

Tonto Team, also tracked under aliases such as Earth Akhlut, BRONZE HUNTLEY, CactusPete, and Karma Panda, is a well-established cyber espionage threat group with a long operational history dating back to at least 2009. This group is widely assessed to be Chinese state-sponsored, with some reporting linking them to the Shenyang Military Region Technical Reconnaissance Bureau (Unit 65017 or Unit 65016).

Their primary motivation is cyber espionage and the theft of intellectual property, objectives that consistently align with China’s geopolitical and economic interests. Initially, Tonto Team’s focus was largely on countries in the Asia-Pacific region, specifically South Korea, Japan, Taiwan, and the United States. However, by 2020, they significantly broadened their operational scope to include other Asian nations like India, Mongolia, and Russia, as well as countries across Eastern Europe and even Switzerland.

Tonto Team maintains a diverse targeting profile, consistently focusing on high-value intelligence collection across various critical sectors. These include government, military and defense organizations, energy, mining, financial institutions, education, healthcare, technology, media, telecommunications, and IT & ITES companies. Their targeting of IT and cybersecurity companies, as seen in their repeated attempts against Group-IB, underscores a strategic interest in supply chain compromises to expand their reach to a broader set of victims.

Tactics & Techniques

Tonto Team exhibits a consistent and adaptable set of tactics, techniques, and procedures (TTPs) that have evolved over more than a decade of operations. Initial access is predominantly gained through sophisticated spear-phishing campaigns. These emails typically carry malicious attachments, often in Rich Text Format (RTF) or other Microsoft Office document formats, crafted using the “Royal Road RTF Weaponizer” toolkit. This toolkit is a known favorite among Chinese advanced persistent threat (APT) groups. These weaponized documents exploit known vulnerabilities in Microsoft Office, particularly within the Equation Editor component (e.g., CVE-2017-11882, CVE-2018-0802, CVE-2018-0798, CVE-2018-8174, CVE-2019-9489, CVE-2020-8468). Successful execution of these exploits often relies on user interaction.

Beyond spear-phishing, Tonto Team has also leveraged compromised Microsoft Exchange servers to deploy web shells for persistent access, notably exploiting ProxyLogon flaws in 2021. For execution, they utilize living-off-the-land binaries and scripts such as PowerShell to download additional payloads and Python-based tools. They also employ techniques like DLL search order hijacking, abusing legitimate signed Microsoft executables to load their malicious DLLs, which helps them evade detection by blending with trusted processes.

Once inside a network, Tonto Team focuses heavily on internal reconnaissance and credential access. They use tools like NBTscan to enumerate network shares and the ShowLocalGroupDetails command to identify accounts on compromised hosts. Privilege escalation is achieved by exploiting vulnerabilities such as CVE-2019-0803 and MS16-032. Credential theft is a central operational component, employing tools like Mimikatz, gsecdump, and LaZagne to extract credentials, hashes, and Kerberos tickets from memory, alongside custom keyloggers. They have also established phishing websites to directly harvest credentials. For lateral movement, Tonto Team has been observed using EternalBlue exploits.

Their command and control (C2) infrastructure is extensive and designed for obfuscation. They route traffic through external servers to hide their origin and are known to maintain at least 80 C2 servers and hundreds of domain names, demonstrating significant operational capability.

Notable Campaigns

Tonto Team has been linked to several significant campaigns throughout its operational history:

  • Heartbeat Campaign (2009-2012): This early campaign targeted government organizations and institutions related to the South Korean government, including political parties, media outlets, and a military branch.
  • Operation Bitter Biscuit (2017): While specific details are less public, this operation is also cited as a notable campaign conducted by the group.
  • Microsoft Exchange Server Exploitation (March 2021): Tonto Team was among the threat actors who exploited the ProxyLogon flaws in Microsoft Exchange Server, targeting cybersecurity and procuring companies in Eastern Europe.
  • Attacks Against Group-IB (March 2021 & June 2022): The group launched two unsuccessful attacks against the cybersecurity firm Group-IB, using phishing emails with Royal Road-crafted documents to deliver Bisonal.DoubleT malware. This indicates a consistent interest in compromising cybersecurity vendors.
  • Increased Targeting of Russia (2022): Coinciding with the Russia-Ukraine conflict, Tonto Team significantly ramped up its cyber espionage efforts against Russian government agencies and scientific and technical enterprises. These campaigns used sanctions-related lures in malicious documents to target defense research institutes, indicating a clear intelligence collection objective.

Associated Malware & Tools

Tonto Team relies on a combination of custom malware and widely available tools to achieve its objectives:

  • Bisonal RAT: This is a longstanding and continuously developed custom backdoor, including its Bisonal.DoubleT variant, which has been in use for over a decade. It provides remote access, command execution, file transfer, and surveillance capabilities.
  • Dexbia: Another custom backdoor frequently deployed by the group.
  • ShadowPad: A modular backdoor with a plugin-based architecture, often deployed via DLL sideloading. ShadowPad is also known to be shared with other prominent Chinese APT groups like APT41/Winnti. It is sometimes referred to as PoisonPlug.
  • TontoTeam.Downloader (QuickMute): A more recently identified downloader used to retrieve next-stage malware from remote servers.
  • Royal Road RTF Weaponizer: A document builder utilized to create malicious RTF files with embedded exploits, a common initial access tool.
  • Credential Dumping Tools: These include well-known utilities such as Mimikatz, gsecdump, LaZagne, and WCE, used for extracting credentials and hashes from compromised systems.
  • Keyloggers: Custom keylogging tools are part of their arsenal for input capture.
  • Network Reconnaissance Tools: NBTscan is used to enumerate network shares.
  • Living off the Land (LotL) Tools: The group frequently uses legitimate system tools like PowerShell and Python for execution and to blend in with normal network activity.

Current Status

Tonto Team remains an active and persistent cyber espionage threat actor. MITRE ATT&CK records for the group were last modified in November 2024, indicating ongoing tracking and relevance. Furthermore, research published in April 2026 confirms that Tonto Team continues to operate as a persistent espionage actor. Cybersecurity firms, including Group-IB in February 2023, have explicitly assessed that Tonto Team will continue to target technology and other critical sectors, particularly through spear-phishing and supply-chain compromises. Their adaptability and consistent evolution of tools and techniques over more than a decade highlight their sustained capability and commitment to their state-sponsored objectives. Organizations, particularly those in the target sectors and regions, should consider Tonto Team a significant and active threat requiring robust, intelligence-led defensive strategies.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call