CSIDB logo
Threat actor

Bronze Butler

Attribution profile

Type
Nation State
Location
China
Known incidents
1 incident
First seen
2014-01-01
Last seen
2014-01-01
Updated
2026-08-01 05:27
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Bronze Butler, also known by the alias Bronze Butler, is a threat actor linked to China and associated with the APT17 threat group. The actor has been observed conducting multi‑year campaigns that focus on government agencies and vertical organizations that rely on region‑specific Japanese software. Their activities are characterized by efforts to gain remote access, move laterally within networks, and exfiltrate data, indicating an espionage‑oriented objective.

The group’s targeting consistently involves entities that use niche Japanese applications such as Sanshiro spreadsheets, Ichitaro word processors, and SkySea Client View management tools. By concentrating on these less‑monitored programs, the actors seek to bypass conventional defenses that are less likely to monitor such specialized software. Their strategic goal appears to be the acquisition of sensitive information from high‑value targets rather than financial gain.

Typical tactics, techniques, and procedures include the delivery of spearphishing emails containing malicious documents designed to exploit zero‑day vulnerabilities in the aforementioned Japanese software. Once initial access is achieved, the actors deploy a suite of malware families—including PlugX, Emdivi, Agtid, NodeRAT, and Wali—to establish persistent remote access, facilitate lateral movement, and enable data exfiltration. They also leverage the limited security scrutiny surrounding these specialized tools to maintain stealth throughout the intrusion lifecycle.

A representative campaign began in January 2014 and continued for several years, during which Bronze Butler and allied APT17 groups exploited zero‑day flaws in Japanese software to infiltrate numerous government and vertical‑sector networks. The operation relied on spearphishing with tailored malicious attachments, resulting in the installation of the aforementioned malware families to support remote control, internal reconnaissance, and the theft of confidential data. This campaign exemplifies the actor’s persistent focus on exploiting overlooked software vectors to achieve espionage objectives.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB