Tick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese National University of Defense and Technology, which is possibly linked to the PLA. This threat actor targets organizations in the critical infrastructure, heavy industry, manufacturing, and international relations sectors for espionage purposes. The attacks appear to be centered on political, media, and engineering sectors. STALKER PANDA has been observed conducting targeted attacks against Japan, Taiwan, Hong Kong, and the United States.
Also known as
Nian, BRONZE BUTLER, REDBALDKNIGHT, STALKER PANDA, G0060, Stalker Taurus, PLA Unit 61419, Swirl Typhoon.
References
- wikileaks.org
- symantec.com
- secureworks.jp
- researchcenter.paloaltonetworks.com
- blog.jpcert.or.jp
- cfr.org
- secureworks.com
- blog.trendmicro.com
- attack.mitre.org
- secureworks.com
- unit42.paloaltonetworks.com
- twitter.com
Actor metadata imported from Malpedia (Fraunhofer FKIE).