[Analysis_Report]Tick_Threat_Group.pdf
ID: 89b9c74d-280e-4eed-bdf9-94755e5828f6
STIX ID: report--89b9c74d-280e-4eed-bdf9-94755e5828f6
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-03-28
Last Modified Date: 2019-03-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Tick Group (aka Bald Knight / Bronze Butler / RedBaldKnight) is a long‑running, targeted espionage actor active since at least 2008 and focused on Korean and Japanese organizations; this AhnLab report describes multiple campaigns and a diverse toolset — downloaders (Bisodown, Gofarer), backdoors (Daserf, Netboy, Datper, Xxmm), keyloggers, credential theft tools (WCE, Mimikatz), builders/controllers (shadowDawn, xxmm builders), steganography use, and extensive IoCs (sample MD5s, domains/URLs).
