Home/Threat Actor/Tonto Team
Threat Actor

Tonto Team

tonto_team · china · active since 2009

Tonto Team (CactusPete / Karma Panda / Bronze Huntley / Earth Akhlut / HeartBeat APT / T-APT-13 / APT-C-09 / G0131) is a suspected China-aligned cyber-espionage cluster active since at least 2009 and one of the longer-running publicly-tracked China- aligned clusters with sixteen-plus years of sustained operations, widely assessed by Korean cybersecurity research community (ESTSecurity, AhnLab, NSHC, S2W) to operate in alignment with People's Liberation Army (PLA) Unit 65017, formerly the PLA Shenyang Military Region Reconnaissance Bureau / 3PLA Bureau 12, reorganized under the Strategic Support Force following the 2015-2016 PLA restructuring, distinguished operationally by two defining victim signatures: (1) sustained Korean Peninsula targeting across more than fifteen years against South Korean government, defense industrial base (KAI, Hanwha, LIG Nex1), KAERI nuclear research, think tanks, and defense-academic targets, and (2) operationally-distinctive Russian and Russian Far East targeting (uncommon among publicly-tracked China-aligned clusters given the broader Sino-Russian strategic partnership) consistent with northeast-Chinese regional intelligence priorities, defined by the signature Bisonal malware family with continuous variant evolution across more than a decade (Cisco Talos' March 2018 "Bisonal, 10 Years of Play" analysis documenting the sustained evolution at that time), Dexbia + ShadowPad + PoisonIvy toolkit, and sustained CVE-2017-11882 Equation Editor exploitation across 2017-2020.

china confidence: medium 24 aliases MITRE ATT&CK G0131 ↗

Profile

Tonto Team (also tracked as CactusPete, Karma Panda, Bronze Huntley, Earth Akhlut, HeartBeat APT, T-APT-13, APT-C-09, and MITRE ATT&CK G0131) is a suspected China-aligned cyber-espionage cluster active since at least 2009, one of the longer-running publicly-tracked China-aligned clusters in the public record, with sixteen-plus years of sustained operations. The cluster is widely assessed by vendor research to operate in alignment with Chinese state intelligence interests. Korean cybersecurity research community vendor assessments, uniquely positioned for Tonto Team tracking given sustained Korean victimology, have suggested operational alignment with People's Liberation Army (PLA) Unit 65017, formerly known as the PLA Shenyang Military Region Reconnaissance Bureau / Third Department Twelfth Bureau (3PLA Bureau 12), now reorganized under the Strategic Support Force following the 2015-2016 PLA restructuring. The Shenyang TRB / Unit 65017 attribution is grounded in operational hours consistent with northeast-China time zones, sustained targeting profile aligned with northeast-Chinese regional intelligence priorities (Korean Peninsula, Japan, Russian Far East, Mongolia), and infrastructure-attribution indicators. Whether the cluster currently operates under post-restructuring Strategic Support Force chain of command or under another PLA element is analytically open. No formal government attribution event has been issued.

the PLA-Unit-65017-suspected framing rests on Korean and international vendor research and should be treated as suspected rather than formally confirmed. Two defining victim signatures distinguish Tonto Team from peer publicly-tracked China-aligned clusters: First, sustained Korean Peninsula targeting across more than fifteen years. Continuous operations against South Korean government, defense industrial base (KAI / Korea Aerospace Industries, Hanwha, LIG Nex1), nuclear research (KAERI / Korea Atomic Energy Research Institute), think tanks, and defense- relevant academic targets. Korean cybersecurity vendors (ESTSecurity, AhnLab, NSHC / Threat Recon, S2W) have published extensive Korean-language tracking documenting continuous operations and represent the most operationally-detailed sustained public-tracking of any China-aligned cluster against South Korea. Second, sustained Russian and Russian Far East targeting. Operations against Russian government, defense, aerospace, and Russian Far East regional targets is operationally distinctive among publicly-tracked China-aligned clusters, most China- aligned clusters do not actively target Russia given the broader Sino-Russian strategic partnership. The Russian targeting pattern reflects the cluster's regional intelligence mission for northeast-Chinese (Shenyang-region) PLA tasking, which has historical institutional interest in Russian Far East military and infrastructure collection. The Russian targeting is among the strongest publicly-available indicators for the Shenyang TRB / PLA Unit 65017 attribution framing and one of the most analytically interesting elements of the cluster's profile. Operationally the cluster's signature toolkit centers on the Bisonal malware family, a Windows backdoor providing command execution, file collection, screenshot capture, and exfiltration capability that has undergone continuous variant evolution across more than a decade. Cisco Talos' March 2018 disclosure "Bisonal, 10 Years of Play" documented the family's sustained evolution at that time.

subsequent Kaspersky, Trend Micro, and Korean-vendor tracking has continued to document Bisonal variant evolution through 2024. Bisonal-presence is among the stronger cluster-attribution signals for Tonto Team / CactusPete / Earth Akhlut activity, though Bisonal variant overlap with other PRC- aligned clusters has been documented and should be treated as one-of-multiple attribution indicators rather than a single- signal attribution. Beyond Bisonal the cluster operates Dexbia (a sibling backdoor), ShadowPad (shared with other PRC-aligned clusters including APT41 and Emissary Panda, ShadowPad-presence-alone insufficient for cluster attribution), PoisonIvy, Cobalt Strike Beacon, DustPan, Sodomy backdoor, Lilith, and China Chopper webshells. The cluster operates a relatively conservative toolkit relative to its operational lifespan, sustained evolution of a small set of signature tools rather than aggressive toolkit diversification. Initial-access tradecraft is predominantly spear-phishing with weaponized Office documents, particularly sustained exploitation of CVE-2017-11882 (Microsoft Office Equation Editor remote code execution) across 2017-2020, which was operationally productive across many state-aligned clusters for years. Other CVEs heavily used include CVE-2014-1761, CVE-2015-2545, CVE-2017-0199, CVE-2018-0798, CVE-2018-0802, and CVE-2022-30190 Follina. The cluster has not consistently demonstrated 0day-development capability and primarily relies on rapid weaponization of disclosed n-day vulnerabilities. A handful of operational notes: First, the cluster's vendor-naming proliferation (Tonto Team / CactusPete / Karma Panda / Bronze Huntley / Earth Akhlut / HeartBeat APT / T-APT-13 / APT-C-09) reflects more than a decade of fragmented vendor tracking. Modern reporting should default to "Tonto Team" as the MITRE-canonical name post-2020. Second, the cluster's COVID-era 2020-2021 medical research institute and hospital targeting represented a temporary deviation from traditional government/military/defense victim category and aligned with reported broader PRC interest in COVID-19-relevant biomedical intelligence during the vaccine- development period. Post-2022, the cluster returned to traditional victim categories. Third, attribution to PLA Unit 65017 / Shenyang TRB specifically , though dominant in Korean vendor reporting, has not been confirmed by formal government attribution. The post-2015 PLA restructuring complicates contemporary attribution since the historical Shenyang TRB / 3PLA Bureau 12 was reorganized under the Strategic Support Force. Treat the PLA-Unit-65017-suspected framing as Korean-vendor-research-consensus but not formally confirmed. Fourth, Korean cybersecurity vendor tracking (ESTSecurity, AhnLab, NSHC, S2W) is among the most operationally-detailed sustained public-tracking of any China-aligned cluster against any single country, a useful operational data source for any defender or researcher working in this victim space.

Aliases

24
tonto teamtonto_teamtontoteamcactuspetecactus petecactus_petekarma pandakarma_pandakarmapandabronze huntleybronze_huntleybronzehuntleyearth akhlutearth_akhlutearthakhlutheartbeat aptheartbeat_aptheartbeataptt-apt-13t_apt_13tapt13g0131atk 174atk174

Notable Campaigns

9
2022-2025Continued Operations (2022-2025)
2020-2021Hospital and Research Institute Targeting (COVID-era 2020-2021)
2020Trend Micro: Earth Akhlut Targets Japan (June 2020)
2018-2024Russian and Russian Far East Targeting (2018-2024)
2018-2020Kaspersky GReAT: CactusPete Disclosures (2018-2020)
2017-2020CVE-2017-11882 Equation Editor Exploitation (2017-2020)
2014-2024Sustained Korean Targeting (2014-2024)
2014-2024Bisonal Malware Family Sustained Evolution (2014-2024)
2012-2013Trend Micro: HeartBeat APT (January 2013)

Attribution & Reporting

Attributed by
Trend MicroKaspersky GReATESETESTSecurity (Korea)AhnLab (Korea)NSHC / Threat Recon (Korea)S2W (Korea)Cisco TalosSentinelOneMandiant / FireEyeCrowdStrikeMicrosoftJPCERT/CCRecorded Future Insikt GroupGroup-IBCluster25Cyfirma360 Threat Intelligence CenterQiAnXin Threat Intelligence Center
Key reporting
reportTrend Micro: HeartBeat APT (January 2013), earliest cluster naming
reportCisco Talos: Bisonal, 10 Years of Play (March 2018), Bisonal malware family historical analysis
reportESET: InvisiMole, Equipped for Surveillance (June 2018), adjacent context
reportKaspersky GReAT: CactusPete APT Group's Updated Bisonal Backdoor (August 2020)
reportKaspersky GReAT: ASRUEX Redux, The Evolution of CactusPete Bisonal
reportTrend Micro: Tonto Team Targets Japanese Organizations (June 2020), Earth Akhlut naming
reportESTSecurity (Korea): Tonto Team Threat Resource (sustained Korean-language tracking, multiple years)
reportAhnLab (Korea): Tonto Team Continued Tracking (sustained Korean-language reporting)
reportNSHC / Threat Recon (Korea): Tonto Team Tracking
reportS2W (Korea): Bisonal Malware Tonto Team Analysis
reportRecorded Future Insikt Group: Tonto Team Tracking (multiple years)
reportQiAnXin Threat Intelligence Center: APT-C-09 Tonto Team Tracking (Chinese-language)
report360 Threat Intelligence Center: APT-C-09 Tracking
reportSekoia: Tonto Team CactusPete China Tracking (2023-2024)
reportCyfirma: Tonto Team China APT Tracking (2024)
reportCluster25: Tonto Team Operational Profile (2022-2024)
reportMalpedia Actor Profile: Tonto Team
reportMITRE ATT&CK Group G0131, Tonto Team

Operational

State sponsor

Suspected China-aligned cyber-espionage cluster, widely assessed by vendor research (Trend Micro 2012 HeartBeat APT initial reporting, Kaspersky 2018-2020 CactusPete tracking, Trend Micro 2020 Earth Akhlut tracking, ESET 2018+ continued reporting, Korean cybersecurity firms ESTSecurity / AhnLab / NSHC sustained tracking) to operate in alignment with Chinese state intelligence interests. Korean cybersecurity research community vendor assessments, uniquely positioned for Tonto Team tracking given sustained Korean victimology, have suggested operational alignment with People's Liberation Army (PLA) Unit 65017, formerly known as the PLA Shenyang Military Region Reconnaissance Bureau / Third Department Twelfth Bureau (3PLA Bureau 12), now reorganized under the Strategic Support Force following the 2015-2016 PLA restructuring. The Shenyang TRB / Unit 65017 attribution is grounded in operational hours consistent with northeast-China time zones, sustained targeting profile aligned with northeast-Chinese regional intelligence priorities (Korean Peninsula, Japan, Russian Far East, Mongolia), and infrastructure- attribution indicators. Whether the cluster currently operates under the post-restructuring Strategic Support Force chain of command or under another PLA element is analytically open. No formal US, UK, EU, Japanese, or Korean government attribution event has been issued.

the PLA-Unit-65017-suspected framing rests on Korean and international vendor research and should be treated as suspected rather than formally confirmed. The cluster has been active since at least 2009, one of the longer-running publicly-tracked China-aligned clusters in the public record.

Motivations
espionage, intelligence_gathering, geopolitical_collection, regional_intelligence, korean_peninsula_collection, japan_collection, russian_far_east_collection, mongolia_collection, economic_espionage, intellectual_property_theft
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASODOMY BACKDOOR
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin