CSIDB logo
Threat actor

Tonto Team

Attribution profile

Type
Nation State
Location
China
Known incidents
1 incident
First seen
2017-04-21
Last seen
2017-04-21
Updated
2026-07-30 21:12
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Tonto Team, also referred to as Tonto team, operates under those aliases in public reporting. The group has been identified as originating from China, with specific ties to the northern part of the country. Public descriptions associate the actor with activities that support North Korean operations as well. These details come from cybersecurity analyses that link the alias to a broader set of Chinese-linked intrusions.

In the publicly reported incident from April 2017, Tonto Team focused its efforts on South Korean military officials who were involved in the deployment of the THAAD missile defense system. The targeting was limited to individuals within the defense sector who held responsibilities related to the anti‑ballistic missile shield. The strategic goal described in the reporting was to gather intelligence and to disrupt the installation of the system, which China had openly opposed. This indicates an espionage‑oriented motive with a secondary aim of causing operational disruption.

The actor’s reported method of initial access relied on spear‑phishing emails that contained malicious attachments. Once a recipient opened the attachment, the attackers were able to gain a foothold in the target’s system. No specific malware families or additional tooling are mentioned in the source material, so the description of their tactics remains limited to this phishing vector. The use of deceptive emails to deliver payloads represents the only confirmed technique in the available reporting.

Attribution placed the activity within a Chinese state‑linked context, with Tonto Team described as associated with northern China and North Korean operations, while another group, APT10, was tied to Chinese military intelligence in the same campaign. The 2017 THAAD‑focused operation is cited as a representative example of the actor’s publicly known activity. No other campaigns are detailed in the provided information, so the profile rests on this single documented operation.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB