Home/Threat Actor/Tick
Threat Actor

Tick

tick_bronze_butler · china · active since 2008

Tick (Bronze Butler / RedBaldknight / Stalker Panda / Nian / G0060) is one of the most operationally durable publicly-tracked China-aligned cyber-espionage clusters, active since 2008 and widely assessed to operate with MSS tasking (Shanghai Bureau adjacency suggested but not formally established), responsible for more than fifteen years of sustained collection against Japanese defense industrial base, aerospace, heavy industry (shipbuilding, automotive, electronics, semiconductors), manufacturing, chemical, pharmaceutical, and healthcare targets , distinguished operationally by sustained Ichitaro Japanese- word-processor zero-day development and exploitation (essentially Japan-specific exploits with no value against non-Japanese targets) and by the signature Daserf + Datper + T-SMB SCAN bespoke toolkit that has evolved across more than a decade with unusual tradecraft discipline relative to peer clusters, with JPCERT/CC's sustained 2019-2024 Japanese-national-CERT advisory series providing among the most operationally-detailed sustained public-tracking of any China-aligned cluster against any single country.

china confidence: high 16 aliases MITRE ATT&CK G0060 ↗

Profile

Tick (also tracked as Bronze Butler, RedBaldknight, Stalker Panda, Nian, and MITRE ATT&CK G0060) is a China-aligned cyber-espionage cluster active since at least 2008, one of the most operationally durable publicly-tracked China-aligned clusters in the public record, with more than fifteen years of sustained operations against Japanese targets. The cluster is widely assessed by vendor research (Dell Secureworks Counter Threat Unit's October 2017 seminal Bronze Butler disclosure, Trend Micro's November 2017 REDBALDKNIGHT disclosure, ESET's ongoing tracking, JPCERT/ CC's sustained Japanese-national-CERT advisory series across 2019-2024, and many others) to operate in alignment with Chinese state interests, most commonly framed as MSS (Ministry of State Security) tasking with some vendor reporting suggesting MSS Shanghai Bureau adjacency. Attribution at the specific MSS-bureau or contractor level has not been formally established by US or Japanese government indictment.

Targeting focus is overwhelmingly directed at Japan, defense industrial base, aerospace, heavy industry (shipbuilding, automotive, electronics, semiconductors), manufacturing, chemical, pharmaceutical, healthcare, biotechnology, higher education, research, and government entities, with selective expansion to South Korean, Russian, mainland Chinese, and Mongolian targets. The Japan-centric victimology is so pronounced and so sustained across more than a decade that Tick is among the most-clearly single-country-focused publicly-tracked clusters. The cluster's most distinctive tradecraft signature is sustained exploitation of Ichitaro, a Japanese-language word processor published by JustSystems and used predominantly within Japanese government and corporate environments.

Ichitaro zero-days (CVE-2014-7247 and others) are essentially Japan-specific exploits, they have no value against non-Japanese targets, and Tick's sustained investment in Ichitaro 0day development across multiple years is unusually strong evidence of the cluster's dedicated Japan-targeting focus. Few other publicly-tracked clusters have invested in Ichitaro exploitation. Operationally Tick's toolkit centers on three signature implants that have evolved across more than a decade: Daserf (the central .NET-based Windows backdoor, observed since approximately 2011 with continuous incremental evolution including the 2017 steganography-based delivery channel disclosed by Trend Micro), Datper (a sibling Windows backdoor sharing infrastructure and tasking patterns with Daserf), and T-SMB SCAN (a bespoke SMB network-reconnaissance and credential-spraying tool that has appeared in Tick operations since at least 2014).

Beyond these three the cluster operates xxmm/Wrapdll, GeminiRAT, SkySilk (newer 2021+ implant), ShadowWalker, HomamDownloader, DownDelph, Minzen, and SidePlay. The sustained use of a small set of bespoke tools across more than a decade, rather than the eclectic open-source-heavy toolkits seen in some peer clusters, reflects the cluster's tradecraft discipline. Initial access patterns mix spear-phishing with weaponized Office documents (CVE-2014-1761, CVE-2017-11882, CVE-2018-0802, and related Office vulnerabilities), spear-phishing with Ichitaro 0day exploits, supply-chain compromise of Japanese software vendors, watering-hole compromises of Japanese industry-relevant websites, and (more recently) exploitation of public-facing vulnerabilities (Exchange ProxyLogon, BlueKeep).

A handful of operational notes: First, the cluster's vendor-naming proliferation (Tick / Bronze Butler / RedBaldknight / Stalker Panda / Nian) reflects more than a decade of fragmented pre-consolidation vendor tracking rather than separate operational sub-clusters. Modern reporting should default to "Tick" as the MITRE-canonical name. Second, the cluster is operationally distinct from BlackTech / Palmerworm (already covered as blacktech.

yaml), which also targets Japanese organizations but operates a different toolkit (Plead, TSCookie, Flagpro, BendyBear, Waterbear) and a different target-pivot pattern (US subsidiary
  • Japanese parent compromise via Cisco router firmware implants). Tick and BlackTech overlap in target country (Japan) but are clearly distinguishable on toolkit, tradecraft, and infrastructure. Third, attribution to MSS specifically, though dominant in vendor reporting, has not been confirmed by formal US or Japanese government attribution. Treat the MSS-tasking framing as suspected. Fourth, JPCERT/CC's sustained advisory series across 2019-2024 is among the most operationally-detailed sustained public- tracking of any China-aligned cluster against any single country, reflecting the depth of Japanese national-CERT investment in Tick-specific tracking, a useful operational data source for any defender or researcher working in this victim space.

Aliases

16
ticktick grouptick_groupbronze butlerbronze_butlerbronzebutlerredbaldknightred baldknightred_baldknightstalker pandastalker_pandaniannian aptg0060atk 36atk36

Notable Campaigns

9
2024-2025Continued Operations (2024-2025)
2021-2023Japanese Shipbuilding and Heavy-Industry Targeting (2021-2023)
2019-2024JPCERT/CC Sustained Tick Advisory Series (2019-2024)
2018-2020ESET: Bronze Butler Expanded Tracking (2018-2020)
2017Dell Secureworks Counter Threat Unit: Bronze Butler (October 2017)
2017Trend Micro: REDBALDKNIGHT / BRONZE BUTLER's Daserf Backdoor Now Using Steganography (November 2017)
2014-2024T-SMB SCAN Lateral Movement Tradecraft Signature
2014-2019Ichitaro Japanese Word Processor Zero-Day Exploitation (2014-2019)
2008-2017Pre-Consolidation Japan-Focused Operations (2008-2017)

Attribution & Reporting

Attributed by
Dell Secureworks Counter Threat UnitJPCERT/CCSymantecTrend MicroESETKasperskyNTT SecurityLAC Co. Ltd. (Japan)Macnica Networks (Japan)CrowdStrikeMandiant / FireEyeMicrosoftCisco TalosSentinelOneRecorded Future Insikt GroupGroup-IBCluster25Cyfirma
Key reporting
reportSymantec: Tick Cyberespionage Group Zeros In on Japan (April 2016)
reportDell Secureworks Counter Threat Unit: BRONZE BUTLER Targets Japanese Businesses (October 12, 2017), seminal international-vendor consolidation
reportTrend Micro: REDBALDKNIGHT / BRONZE BUTLER's Daserf Backdoor Now Using Steganography (November 2017)
reportESET: Tick / Bronze Butler Targets Japan (Operation Trident Tick, May 2022)
reportESET: Operation StealthyTrident, Tick Backdoor Analysis (May 2020)
reportJPCERT/CC: Tick Activity Alerts (Japanese-language and English-language, multiple years 2019-2024)
reportLAC Co. Ltd.: Tick Cyber Threat Analysis (Japanese-language, multiple years)
reportMacnica Networks: Trend Analysis of Targeted Attacks Aimed at Japanese Organizations (multiple years)
reportNTT Security: Global Threat Intelligence Report Tick Section (multiple years)
reportSecureworks: BRONZE BUTLER Threat Profile (ongoing)
reportCisco Talos: Bronze Union Update (December 2018), adjacent context
reportCluster25: Tick Operational Profile (2022-2024)
reportCyfirma: Tick Bronze Butler Tracking (multiple years)
reportMalpedia Actor Profile: Tick
reportMITRE ATT&CK Group G0060, Tick

Operational

State sponsor

Suspected China-aligned advanced persistent threat group, widely assessed by vendor research (Symantec, Dell Secureworks, JPCERT, Trend Micro, ESET, Kaspersky, NTT Security, and others) to operate in alignment with Chinese state interests, most commonly framed as MSS (Ministry of State Security) tasking, with some vendor reporting suggesting MSS Shanghai Bureau adjacency though the geographic-bureau attribution remains suggested rather than formally established. The cluster has been active for an unusually long publicly-documented period (since at least 2008) and is one of the most operationally durable China-aligned clusters in the public record. Attribution at the specific MSS-bureau or contractor level has not been formally established by US or Japanese government indictment.

no DOJ or Japanese government prosecution has named individual operators. However, vendor consensus on China-aligned attribution is uniform across more than fifteen years of public tracking.

Motivations
espionage, intelligence_gathering, economic_espionage, intellectual_property_theft, geopolitical_collection, defense_industrial_collection, heavy_industry_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MINZENMSHTASHADOW WALKERSHADOWWALKERSIDE PLAYSIDE WALKSIDEPLAYSIDEWALKSKY SILKSKYSILK
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin