15
Techniques
6
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About Tonto Team

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

View MITRE record ↗

Toolsets (6)
🐛
Bisonal S0268
Malware · Windows
🐛
ShadowPad S0596
Malware · Windows
🔧
LaZagne S0349
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
NBTscan S0590
Tool · Windows, Linux, macOS
🔧
gsecdump S0008
Tool · Windows
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2017-0176View full details on NVD
↑