Uptime Hamster: 10d 6h 39mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Tick

Tick

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: BRONZE BUTLER, G0060, Nian, PLA Unit 61419, REDBALDKNIGHT, STALKER PANDA, Stalker Taurus, Swirl Typhoon, apt-c-50, RedControle, StickyKeys, APT REDBALDKNIGHT, APT TICK, research, Powerkatz, Password Dumper, PTH, DCSync
Ver en IntelTracker → APTTrail →
Tick, also known by aliases such as Bronze Butler and REDBALDKNIGHT, is a long-standing cyber espionage advanced persistent threat (APT) group believed to be operating out of China, with some reports linking it to the People's Liberation Army (PLA) Unit 61419. The group emerged as early as 2006 and has consistently focused on persistent access for intelligence gathering rather than large-scale, disruptive attacks. Their primary motivation is cyberespionage, aimed at acquiring sensitive political, diplomatic, military, and industrial information, as well as intellectual property and product details to benefit Chinese strategic interests and gain industrial advantage. What sets Tick apart is its disciplined approach to sustained, covert operations, its methodical improvement of malware over time, and its propensity to exploit region-specific software vulnerabilities, especially within Japanese and South Korean enterprises. The group operates under multiple names, including BRONZE BUTLER,

Aliases del actor

BRONZE BUTLERG0060NianPLA Unit 61419REDBALDKNIGHTSTALKER PANDAStalker TaurusSwirl Typhoonapt-c-50RedControleStickyKeysAPT REDBALDKNIGHTAPT TICKresearchPowerkatzPassword DumperPTHDCSyncSkeletonKeyGoldenSilver Ticketsotrosse clasifica dentro de la categoría "Malware / Tools"

Actores similares

apt-deathstalkeractor · 1apt-redbaldknightactor · 1apt-tickactor · 1apt-flaxtyphoonactor · 1apt-goldenbirdactor · 1apt-goldenjackalactor · 1apt-goldenratactor · 1apt-platinumactor · 1apt-sharppandaactor · 1apt-twistedpandaactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownblogs.jpcert.or.jpAPT TICK indicators and references
DLS / leak siteunknownimage.ahnlab.comAPT TICK indicators and references
DLS / leak siteunknownotx.alienvault.comAPT TICK indicators and references
DLS / leak siteunknownpastebin.comAPT TICK indicators and references
DLS / leak siteunknownwww.welivesecurity.comAPT TICK indicators and references
Repositoriounknowngithub.comAPT TICK indicators and references
DLS / leak siteunknownraw.githubusercontent.comAPT TICK indicators and references
DLS / leak siteunknown103.127.124.117APTTrailURLhttpAPT TICK indicators and references
Forounknownwww.breachsense.comticketclub.it - RaidForums Data Breach
Forounknowngetbootstrap.comticketclub.it - RaidForums Data Breach
Forounknowngithub.comticketclub.it - RaidForums Data Breach
Forounknowngithub.comticketclub.it - RaidForums Data Breach
DLS / leak siteunknownduckduckgo.comTick (China)
DLS / leak siteunknownduckduckgo.comTick (China)
Motivacion