{
  "family": "tick",
  "sample_count": 1,
  "category": "backdoor",
  "description": "<h3>Executive Summary</h3>\nTick (also known as Bronze Butler, REDBALDknight, or Stalker Panda) is a highly sophisticated Advanced Persistent Threat (APT) group believed to be operating out of East Asia. Active since at least 2006, Tick primarily targets government agencies, defense contractors, heavy industry, and high-tech manufacturing sectors, heavily focusing its operations on targets in Japan and South Korea. Their primary objective is long-term cyber espionage and the exfiltration of highly sensitive intellectual property.\n\n<h3>Tactics, Techniques, and Procedures (TTPs)</h3>\nTick is characterized by its patience, advanced evasion techniques, and the use of a diverse arsenal of custom-developed malware alongside repurposed open-source tools.\n\nKey aspects of Tick's operational playbook include:\n<ul>\n<li><strong>Initial Access:</strong> The group frequently relies on zero-day vulnerabilities in regional enterprise software (such as popular Japanese asset management solutions) or highly targeted spear-phishing emails utilizing exploit-laden Office documents.</li>\n<li><strong>Custom Malware Arsenal:</strong> Tick deploys a variety of proprietary malware families, including <strong>Daserf</strong> (a sophisticated backdoor used for lateral movement and command execution), <strong>Minzen</strong> (a downloader), <strong>Datper</strong> (a RAT), and <strong>Xxmm</strong>. These tools are heavily obfuscated and frequently updated to evade signature-based detection.</li>\n<li><strong>Living off the Land (LotL):</strong> To maintain absolute stealth during lateral movement and data exfiltration, Tick operators heavily utilize legitimate administrative tools (like PowerShell, Windows Management Instrumentation (WMI), and PsExec) and legitimate cloud storage services to exfiltrate stolen data, blending their activities with normal administrative traffic.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nAn intrusion by the Tick APT group is a critical, \"nation-state level\" security incident. Their prolonged dwell times and focus on high-value intellectual property mean that a successful breach often results in devastating strategic and economic damage to the targeted organization.\n\n<h3>Defense and Resilience Strategies</h3>\n<ul>\n<li><strong>Behavioral EDR and Threat Hunting:</strong> Defending against Tick requires mature EDR capabilities and active threat hunting. Security teams must monitor for anomalous usage of administrative tools (LotL techniques), unusual WMI queries, and unexpected lateral movement across the network.</li>\n<li><strong>Vulnerability Management:</strong> Given their history of exploiting regional enterprise software, organizations must maintain strict, accelerated patch management protocols, particularly for edge devices and specialized corporate applications.</li>\n<li><strong>Network Segmentation and DLP:</strong> Implement rigorous network segmentation to contain potential breaches. Deploy robust Data Loss Prevention (DLP) solutions to monitor for the bulk extraction of sensitive documents or CAD files to unauthorized external or cloud storage endpoints.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "APT.Tick",
    "Bronze Butler",
    "REDBALDknight",
    "Stalker Panda"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1192",
    "T1059.001",
    "T1047",
    "T1567.002"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:42:48Z",
  "type": "APT Group",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}