THREAT_ACTOR · G0131
Tonto Team
Also known as: Tonto Team, Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda
Profile
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).
MITRE ATT&CK ↗Techniques
15 ATT&CK techniques attributed to this actor.
Software
6 malware/tools attributed to this actor.
Related corpus activity
9,626 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Tonto Team.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2017-17215 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2025-34085 | cve | — | 85 | 1 |
| cve-2025-1055 | cve | ransomware | 85 | 3 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2023-52271 | cve | ransomware | 85 | 3 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2025-61155 | cve | ransomware | 85 | 3 |
| cve-2021-27137 | cve | — | 85 | 8 |
Showing the top 30 by severity of 9,626.