CSIDB logo
Threat actor

Bronze Butler

Attribution profile

Type
Nation State
Location
China
Known incidents
6 incidents
First seen
2012-09-26
Last seen
2021-02-04
Updated
2026-08-01 04:39
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Bronze Butler, also known as Tick, is a threat actor that has been linked to China in open‑source reporting. The group is described in public sources as a suspected state‑backed, Chinese‑linked cyber‑espionage operation that has targeted organizations in Europe and Asia. Its observed victims include a French cybersecurity firm, Japanese defense contractors such as Pasco Corporation and NEC, Japanese electronics and defense companies, Mitsubishi Electric, Kobe Steel, and a South Korean defense contractor. The reported intrusions have involved the theft of client information, source code for government‑certified firewall products, employee personal data, corporate documents related to government agencies, and defense‑related information such as submarine sensor data and contract details. These activities indicate an espionage‑oriented focus rather than financially motivated crime.

The group’s reported tactics, techniques and procedures include spearphishing emails that deliver malicious payloads, the use of zero‑day exploits to gain initial access, and the deployment of custom malware such as SymonLoader. In several campaigns the actors have deleted logs to obscure their presence and have employed trojanized legitimate software—such as Korean‑language industrial utilities and a Japanese GO game—to deliver their payloads. In one notable operation they weaponized secure USB drives certified under national security guidelines, using the drives to bypass air‑gap protections and extract data from isolated networks. These methods demonstrate a focus on stealth, persistence and the ability to traverse both network‑connected and air‑gapped environments.

Representative operations attributed to Bronze Butler/Tick include the February 2021 intrusion into the French firm Stormshield, where client data and source code for a government‑certified firewall were exfiltrated; the June 2019 breach of Mitsubishi Electric that exposed employee and retiree personal information along with sensitive corporate documents; the May 2018 intrusion at Pasco Corporation, a Japanese defense contractor, which involved spearphishing and zero‑day exploits; the December 2016 incident at a Japanese electronics and defense contractor where approximately 28,000 files were accessed, including potential submarine sensor data; the June 2015 compromise of Kobe Steel that involved Ministry of Defense‑related data and personal information; and the September 2012 attack on a South Korean defense contractor that used weaponized USB drives to deliver SymonLoader and extract data from air‑gapped systems. These incidents illustrate a pattern of targeting defense‑related and high‑value entities across multiple geographic regions using a blend of social engineering, exploit‑based intrusion and specialized malware.

Incidents

Attributed incidents are available to members.

6 incidents
CSIDB