Tonto Team
Also reported as Earth Akhlut, CactusPete, BRONZE HUNTLEY, TAG-74, Karma Panda and 10 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1003.001 1 report reports only
- T1003.002 1 report reports only
- T1007 1 report reports only
- T1016 1 report reports only
- T1021.002 1 report reports only
- T1055.012 1 report reports only
- T1057 1 report reports only
- T1059.001 1 report in ATT&CK
- T1059.003 1 report reports only
- T1071 1 report reports only
Show all 20 techniques Show fewer
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2014-1761 KEV
- CVE-2015-1641 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2016-0099 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
Show all 94 CVEs Show fewer
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8570
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-16098
- CVE-2019-16759 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-9489
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-15782
- CVE-2020-1664
- CVE-2020-17530 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2551 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-36958
- CVE-2021-4034 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-1040 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2023-46747 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HART as an Attack Vector
-
Tonto Team, HartBeat, Karma Panda
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Tonto Team, HartBeat, Karma Panda
Show all 129 reports Show fewer
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Targets of Interest - Russian Organizations Increasingly Under Attack By Chinese APTs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Targets of Interest - Russian Organizations Increasingly Under Attack By Chinese APTs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis
-
ShadowPad Malware Analysis _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis _ Secureworks
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
The original link failed its last check. Original publisher Detailsfor Презентация PowerPoint
-
PortDoor: New Chinese APT Backdoor Attack Targets Russian Defense Sector
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor PortDoor: New Chinese APT Backdoor Attack Targets Russian Defense Sector
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
Examining Exchange Exploitation and its Lessons for Defenders
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Examining Exchange Exploitation and its Lessons for Defenders
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
The original link failed its last check. Original publisher Detailsfor winnti-2020-rus.pdf
-
CactusPete APT group’s updated Bisonal backdoor _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CactusPete APT group’s updated Bisonal backdoor _ Securelist
-
CactusPete APT group’s updated Bisonal backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CactusPete APT group’s updated Bisonal backdoor
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
APT_trends_report_Q1_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2019_Securelist
-
The original link failed its last check. Original publisher Detailsfor 중국 기반 해커, 국내 에너지 기관 공격
-
The original link failed its last check. Original publisher Detailsfor ASEC%20REPORT_vol.93_ENG.pdf
-
The original link failed its last check. Original publisher Detailsfor Accenture Strategy Templates
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
-
Threat Actors Target Government of Belarus Using CMSTAR Trojan
The original link failed its last check. Original publisher Detailsfor Threat Actors Target Government of Belarus Using CMSTAR Trojan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
Newest first. Details opens the report in Explore.