Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0060
MITRE ATT&CK Group

BRONZE BUTLER (G0060)

REDBALDKNIGHTTick
ShareXLinkedInRedditHN

[BRONZE BUTLER](https://attack.mitre.org/groups/G0060) is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.(Citation: Trend Micro Daserf Nov 2017)(Citation: Secureworks BRONZE BUTLER Oct 2017)(Citation: Trend Micro Tick November 2019)

▪Techniques used (40)

T1140Deobfuscate/Decode Files or InformationT1005Data from Local SystemT1007System Service DiscoveryT1070.004File DeletionT1059.006PythonT1566.001Spearphishing AttachmentT1036.005Match Legitimate Resource Name or LocationT1113Screen CaptureT1036MasqueradingT1588.002ToolT1548.002Bypass User Account ControlT1059.005Visual BasicT1132.001Standard EncodingT1518Software DiscoveryT1071.001Web ProtocolsT1039Data from Network Shared DriveT1685Disable or Modify ToolsT1124System Time DiscoveryT1189Drive-by CompromiseT1574.001DLLT1003.001LSASS MemoryT1203Exploitation for Client ExecutionT1018Remote System DiscoveryT1560.001Archive via UtilityT1053.002AtT1102.001Dead Drop ResolverT1053.005Scheduled TaskT1080Taint Shared ContentT1204.002Malicious FileT1027.001Binary PaddingT1547.001Registry Run Keys / Startup FolderT1059.001PowerShellT1059.003Windows Command ShellT1105Ingress Tool TransferT1550.003Pass the TicketT1573.001Symmetric CryptographyT1027.003SteganographyT1087.002Domain AccountT1083File and Directory DiscoveryT1036.002Right-to-Left Override

▪Software used (14)

S0002MimikatztoolS0471build_downermalwareS0106cmdtoolS0469ABKmalwareS0110attoolS0470BBKmalwareS0111schtaskstoolS0472down_newmalwareS0187DaserfmalwareS0039NettoolS0596ShadowPadmalwareS0005Windows Credential EditortoolS0008gsecdumptoolS0473Avengermalware
G0060on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.