LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0060: BRONZE BUTLER

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.[1][2][3]

EnterpriseG0060GroupObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BRONZE BUTLER is an ATT&CK group entry for a long-running cyber espionage actor described by MITRE as likely Chinese in origin and primarily focused on Japanese organizations, especially government, biotechnology, electronics manufacturing, and industrial chemistry. The business relevance is not a single exploit; it is the pattern of espionage tradecraft tied to credential theft, Windows command-line administration, scheduled execution, backdoors/downloaders, data discovery, and stealth techniques. Organizations with similar sector, geography, supplier, or partner exposure should use this entry to validate whether identity, endpoint, and network monitoring can support an investigation if comparable behaviors appear.

Executive priority

Treat this as a resilience and intelligence-prioritization signal, not proof of exposure. Leadership should ask whether high-value intellectual property, government-facing operations, manufacturing environments, and Japan-connected business units have sufficient credential protection, endpoint visibility, network-share governance, and incident response evidence retention. Budget decisions should prioritize controls that reduce credential dumping risk, detect suspicious use of native administration tools, and preserve logs needed to prove whether data access or staging occurred.

Technical view

ATT&CK does not provide a dedicated detection section for this group, so SOC and IR teams should pivot from the relationships. BRONZE BUTLER is linked to Windows-focused credential dumping tools such as Mimikatz, Windows Credential Editor, and gsecdump; native utilities such as cmd, Net, at, and schtasks; backdoors/downloaders including Daserf, ABK, BBK, build_downer, down_new, Avenger, and ShadowPad; and techniques including LSASS Memory, local and network-share data collection, system service and remote system discovery, masquerading, RTLO, binary padding, and steganography. Validate whether detections correlate suspicious process execution, credential-access indicators, scheduled task creation, discovery commands, unusual access to shares, and anomalous files or media used for concealment.

Likely telemetry

  • Windows endpoint process creation and command-line logging for cmd, net, at, schtasks, service discovery, and remote system discovery activity
  • Security events and EDR telemetry related to LSASS access, credential dumping tools, suspicious handle access, memory dumping, or abnormal credential material access
  • Scheduled task creation, modification, and execution logs
  • Service enumeration and system discovery command activity
  • File creation, rename, metadata, path, and extension telemetry to support masquerading, RTLO, binary padding, and suspicious placement analysis

Detection direction

  • Prioritize behavior-based analytics over hashes because the relationship set includes public tools, native Windows utilities, masquerading, padding, and steganography that can weaken simple signature matching.
  • Tune for suspicious combinations: credential access followed by discovery, scheduled execution, network-share browsing, or outbound downloader/backdoor activity from the same host or account.
  • Establish baselines for legitimate administrative use of cmd, Net, at, and schtasks; false positives are likely where IT operations use these tools routinely.
  • Validate that LSASS access detections include both known tools and generic suspicious access patterns, not only named malware families.
  • Review whether file and email/security tooling can surface RTLO characters, deceptive filenames, oversized padded binaries, and unexpected media files used in workflows where steganography would be abnormal.

Mitigation priorities

  • Harden credential exposure first: restrict administrative privileges, reduce interactive privileged logons, monitor or protect LSASS, and ensure rapid credential rotation procedures are available for IR.
  • Constrain and monitor native administration utilities through least privilege, application control where appropriate, and alerting on abnormal use of cmd, Net, at, and schtasks.
  • Improve network-share governance by limiting broad access, auditing sensitive repositories, and reviewing whether file servers retain usable access logs for investigations.
  • Strengthen endpoint prevention and detection for downloader/backdoor execution, suspicious scheduled tasks, masqueraded binaries, and unexpected persistence mechanisms.
  • Maintain threat intelligence watchlists for the listed aliases and related software names, while avoiding overreliance on names alone for detection decisions.
Additional notes and limits

The most decision-useful aspects of this ATT&CK object come from its relationships: Windows credential dumping, native command use, scheduled task execution, downloaders/backdoors, discovery, collection, and stealth. This supports practical validation of SOC visibility and IR readiness without assuming the organization is being targeted. Alias handling matters because the group is also referenced as REDBALDKNIGHT and Tick.

MITRE provides no official detection text, no platforms on the group object itself, and no group-level tactics in the supplied fields. Platform and behavior guidance here is inferred only from the supplied related software and technique relationships. Local environment baselines, asset criticality, geography, sector exposure, and retained telemetry are required before drawing conclusions about risk or coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BRONZE BUTLER

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

40 rows
DomainIDNameRelationship / procedure
EnterpriseT1140Deobfuscate/Decode Files or Information

BRONZE BUTLER downloads encoded payloads and decodes them on the victim.[2]

EnterpriseT1005Data from Local System

BRONZE BUTLER has exfiltrated files stolen from local systems.[2]

EnterpriseT1007System Service Discovery

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.[3]

EnterpriseT1070.004File DeletionSub-technique

The BRONZE BUTLER uploader or malware the uploader uses command to delete the RAR archives after they have been exfiltrated.[2]

EnterpriseT1059.006PythonSub-technique

BRONZE BUTLER has made use of Python-based remote access tools.[3]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims.[4][3]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.[2]

EnterpriseT1113Screen Capture

BRONZE BUTLER has used a tool to capture screenshots.[2][3]

EnterpriseT1036Masquerading

BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF.[3]

EnterpriseT1588.002ToolSub-technique

BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor.[4]

EnterpriseT1548.002Bypass User Account ControlSub-technique

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.[2][3]

EnterpriseT1059.005Visual BasicSub-technique

BRONZE BUTLER has used VBS and VBE scripts for execution.[2][3]

EnterpriseT1132.001Standard EncodingSub-technique

Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server.[2]

EnterpriseT1518Software Discovery

BRONZE BUTLER has used tools to enumerate software installed on an infected host.[3]

EnterpriseT1071.001Web ProtocolsSub-technique

BRONZE BUTLER malware has used HTTP for C2.[2]

EnterpriseT1039Data from Network Shared Drive

BRONZE BUTLER has exfiltrated files stolen from file shares.[2]

EnterpriseT1685Disable or Modify Tools

BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes.[3]

EnterpriseT1124System Time Discovery

BRONZE BUTLER has used net time to check the local time on a target system.[2]

EnterpriseT1189Drive-by Compromise

BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks.[4]

EnterpriseT1574.001DLLSub-technique

BRONZE BUTLER has used legitimate applications to side-load malicious DLLs.[3]

EnterpriseT1003.001LSASS MemorySub-technique

BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping.[2]

EnterpriseT1203Exploitation for Client Execution

BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution.[4][3]

EnterpriseT1018Remote System Discovery

BRONZE BUTLER typically use ping and Net to enumerate systems.[2]

EnterpriseT1560.001Archive via UtilitySub-technique

BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration.[2][3]

EnterpriseT1053.002AtSub-technique

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.[2]

EnterpriseT1102.001Dead Drop ResolverSub-technique

BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads.[2]

EnterpriseT1053.005Scheduled TaskSub-technique

BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement.[2]

EnterpriseT1080Taint Shared Content

BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share.[2]

EnterpriseT1204.002Malicious FileSub-technique

BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails.[4][3]

EnterpriseT1027.001Binary PaddingSub-technique

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.[2][3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence.[2]

EnterpriseT1059.001PowerShellSub-technique

BRONZE BUTLER has used PowerShell for execution.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

BRONZE BUTLER has used batch scripts and the command-line interface for execution.[2]

EnterpriseT1105Ingress Tool Transfer

BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget).[2]

EnterpriseT1550.003Pass the TicketSub-technique

BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access.[2]

EnterpriseT1573.001Symmetric CryptographySub-technique

BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server.[2]

EnterpriseT1027.003SteganographySub-technique

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.[3]

EnterpriseT1087.002Domain AccountSub-technique

BRONZE BUTLER has used net user /domain to identify account information.[2]

EnterpriseT1083File and Directory Discovery

BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal.[2]

EnterpriseT1036.002Right-to-Left OverrideSub-technique

BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware.[3]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0106: cmd

cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities. [1]

Cmd.exe contains native functionality to perform many operations to interact with the system, including listing files in a directory (e.g., dir [2]), deleting files (e.g., del [3]), and copying files (e.g., copy [4]).

Windows
ToolEnterprise

S0110: at

at is used to schedule tasks on a system to run at a specified date or time.[1][2]

LinuxWindowsmacOS
ToolEnterprise

S0111: schtasks

schtasks is used to schedule execution of programs or scripts on a Windows system to run at a specific date and time. [1]

Windows
MalwareEnterprise

S0187: Daserf

Daserf is a backdoor that has been used to spy on and steal from Japanese, South Korean, Russian, Singaporean, and Chinese victims. Researchers have identified versions written in both Visual C and Delphi. [1] [2]

Windows
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
MalwareEnterprise

S0596: ShadowPad

ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups. [1][2][3]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
05416eb8afb682f5...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundle05416eb8afb6…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Trend Micro Daserf Nov 2017

    Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.

  2. [2]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  3. [3]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  4. [4]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  5. [5]
    Recorded Future RedEcho Feb 2021

    Insikt Group. (2021, February 28). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved March 22, 2021.

    Open source URL
  6. [6]
    BRONZE BUTLER

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Trend Micro Tick November 2019)

  7. [7]
    BRONZE BUTLER

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Trend Micro Tick November 2019)

  8. [8]
    BRONZE BUTLER

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Trend Micro Tick November 2019)

  9. [9]
    REDBALDKNIGHT

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Trend Micro Tick November 2019)

  10. [10]
    REDBALDKNIGHT

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Trend Micro Tick November 2019)

  11. [11]
    REDBALDKNIGHT

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Trend Micro Tick November 2019)

  12. [12]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  13. [13]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  14. [14]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  15. [15]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  16. [16]
    Tick

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Symantec Tick Apr 2016)(Citation: Trend Micro Tick November 2019)

  17. [17]
    Tick

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Symantec Tick Apr 2016)(Citation: Trend Micro Tick November 2019)

  18. [18]
    Tick

    (Citation: Trend Micro Daserf Nov 2017)(Citation: Symantec Tick Apr 2016)(Citation: Trend Micro Tick November 2019)

  19. [19]
    Trend Micro Daserf Nov 2017

    Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.

  20. [20]
    Trend Micro Daserf Nov 2017

    Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.

  21. [21]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  22. [22]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  23. [23]
    mitre-attackG0060
    Open source URL
  24. [24]
    mitre-attackG0060
    Open source URL
  25. [25]
    mitre-attackG0060
    Open source URL
  26. [26]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  27. [27]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  28. [28]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  29. [29]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  30. [30]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  31. [31]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  32. [32]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  33. [33]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  34. [34]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  35. [35]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  36. [36]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  37. [37]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  38. [38]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  39. [39]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  40. [40]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  41. [41]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  42. [42]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  43. [43]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  44. [44]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  45. [45]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  46. [46]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  47. [47]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  48. [48]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  49. [49]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  50. [50]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  51. [51]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  52. [52]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  53. [53]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  54. [54]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  55. [55]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  56. [56]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  57. [57]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  58. [58]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  59. [59]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  60. [60]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  61. [61]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  62. [62]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  63. [63]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  64. [64]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  65. [65]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  66. [66]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  67. [67]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  68. [68]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  69. [69]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  70. [70]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  71. [71]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  72. [72]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  73. [73]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  74. [74]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  75. [75]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  76. [76]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  77. [77]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  78. [78]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  79. [79]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  80. [80]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  81. [81]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  82. [82]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  83. [83]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  84. [84]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  85. [85]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  86. [86]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  87. [87]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  88. [88]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  89. [89]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  90. [90]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  91. [91]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  92. [92]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  93. [93]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  94. [94]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  95. [95]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  96. [96]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  97. [97]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  98. [98]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  99. [99]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  100. [100]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  101. [101]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  102. [102]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  103. [103]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  104. [104]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  105. [105]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  106. [106]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  107. [107]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  108. [108]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  109. [109]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  110. [110]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  111. [111]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  112. [112]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  113. [113]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  114. [114]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  115. [115]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  116. [116]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  117. [117]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  118. [118]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  119. [119]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  120. [120]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  121. [121]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  122. [122]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  123. [123]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  124. [124]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  125. [125]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  126. [126]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  127. [127]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  128. [128]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  129. [129]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  130. [130]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  131. [131]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  132. [132]
    Trend Micro Daserf Nov 2017

    Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.

  133. [133]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  134. [134]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  135. [135]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  136. [136]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  137. [137]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  138. [138]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  139. [139]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  140. [140]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  141. [141]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  142. [142]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.