Threat actor · all actors
Tonto TeamG0131 state
🇨🇳 CN
aka Tonto Team, Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda, COPPER, Red Beifang, G0131, PLA Unit 65017, TAG-74, LONE CASTLE
Last updated: 2026-08-22
About this actor
[Tonto Team](https://attack.mitre.org/groups/G0131) is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. [Tonto Team](https://attack.mitre.org/groups/G0131) has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).(Citation: Kaspersky CactusPete Aug 2020)(Citation: ESET Exchange Mar 2021)(Citation: FireEye Chinese Espionage October 2019)(Citation: ARS Technica China Hack SK April 2017)(Citation: Trend Micro HeartBeat Campaign January 2013)(Citation: Talos Bisonal 10 Years March 2020)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Secureworkscolour-metal names
Recorded FutureTAG id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 23 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
- 2019 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2019-9489 | 6.2 | 7.5 | 0.0226 | 2019-04-05 | see CVE |
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1056Input Capture ↗T1056.001Keylogging ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.006Python ↗T1068Exploitation for Privilege Escalation ↗T1069Permission Groups Discovery ↗T1069.001Local Groups ↗T1090Proxy ↗T1090.002External Proxy ↗T1105Ingress Tool Transfer ↗T1135Network Share Discovery ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.002Malicious File ↗T1210Exploitation of Remote Services ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 19 / 23 | 83% |
CM-6 | 18 / 23 | 78% |
CM-2 | 17 / 23 | 74% |
SI-3 | 16 / 23 | 70% |
CA-7 | 13 / 23 | 57% |
AC-4 | 12 / 23 | 52% |
CM-7 | 12 / 23 | 52% |
SI-2 | 12 / 23 | 52% |
SI-7 | 12 / 23 | 52% |
AC-6 | 10 / 23 | 43% |
SC-7 | 10 / 23 | 43% |
AC-2 | 9 / 23 | 39% |
AC-3 | 9 / 23 | 39% |
RA-5 | 9 / 23 | 39% |
SI-10 | 8 / 23 | 35% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
- SolarWinds Compromise 1 shared CVEs
Similar actors
Similar TTPs
- PLATINUM 0.31
- TA459 0.29
- Ajax Security Team 0.27
- Whitefly 0.27
- Nomadic Octopus 0.26
Active in same years
- BlackByte 2.00
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00