logo

[Analysis_Report]Tick_Threat_Group.pdf

ID: 89b9c74d-280e-4eed-bdf9-94755e5828f6

STIX ID: report--89b9c74d-280e-4eed-bdf9-94755e5828f6

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-03-28

Last Modified Date: 2019-03-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Tick Group (aka Bald Knight / Bronze Butler / RedBaldKnight) is a long‑running, targeted espionage actor active since at least 2008 and focused on Korean and Japanese organizations; this AhnLab report describes multiple campaigns and a diverse toolset — downloaders (Bisodown, Gofarer), backdoors (Daserf, Netboy, Datper, Xxmm), keyloggers, credential theft tools (WCE, Mimikatz), builders/controllers (shadowDawn, xxmm builders), steganography use, and extensive IoCs (sample MD5s, domains/URLs).