FlagThis
← Threat Actors
/
China
/
Tick
DOSSIER // TICK
Tick
ACTIVE CAMPAIGN TRACKED
▲ High Threat
China
Primary Aliases:
STALKER PANDA
Swirl Typhoon
UNC2814
BRONZE BUTLER
🔍 Adversary Rosetta Stone (11) ▾
📋 Copy All
Sponsor / State Affiliation
China
Primary Motivation
Strategic Espionage and Intelligence Gathering
Active Timeline
Unknown – Present
Confidence Rating
85% (Grounded)
Edge Infrastructure Exploitation Campaign, Southeast Asian Telecommunications Espionage
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Government
Defense
Telecommunications
Critical Infrastructure
Diplomatic Entities
Information Technology
Southeast Asian Regional Organizations
🛡️ MITRE ATT&CK® Attack Lifecycle
(7 TTPs)
📥 Download Navigator JSON
All Stages
7
Initial Access
3
Execution
1
Persistence & Privilege Escalation
1
Credential Access & Discovery
1
Command & Control
1
Initial Access
3
T1566
Exploitation of Edge Network Devices (e.g., VPNs, Firewalls, Routers)
↗
T1566
Spearphishing
↗
T1566
Lateral Movement using Valid Accounts
↗
Execution
1
T1059
Living-off-the-Land (LotL)
↗
Persistence & Privilege Escalation
1
T1547
Web Shell Deployment
↗
Credential Access & Discovery
1
T1003
Credential Access via Memory Injection
↗
Command & Control
1
T1071
Command and Control (C2) via Legitimate Cloud Services
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Iranian-Linked Cyber Av3ngers Campaign Targeting Unitronics PLCs
Attacks and Vulnerabilities
2026-08-16
[DEEP DIVE]
Iranian APT42 and APT35 Utilizing LLMs for AI-Augmented Spear-Phishing and Tamecat Malware Deployment
Attacks and Vulnerabilities
2026-08-15
[DEEP DIVE]
Iranian APT Escalation: Massive Surge in Cyber Operations Against Israeli Infrastructure
Attacks and Vulnerabilities
2026-07-06
[DEEP DIVE]
AI-Augmented Campaign Targeting Siemens S7 Series PLCs
Attacks and Vulnerabilities
2026-08-20
[DEEP DIVE]
US Sanctions Iranian Crypto Exchange Nobitex for Facilitating Ransomware
Miscellaneous
2026-06-05
[DEEP DIVE]
Greyvibe: Russia-Aligned Threat Actor Leverages ChatGPT, Google Gemini, and Ideogram AI for Ukrainian Intelligence Campaigns
Attacks and Vulnerabilities
2026-05-30
Adversary Rosetta Stone // Tick
×
🪟 Microsoft Threat Actor Naming
Swirl Typhoon
📋
🦅 CrowdStrike Monikers
STALKER PANDA
📋
🔍 Mandiant / Google Threat Intel
UNC2814
📋
🏛️ Government / CISA / Law Enforcement
PLA Unit 61419
📋
🛡️ Other Industry Tracking Codes
BRONZE BUTLER
📋
G0060
📋
Nian
📋
REDBALDKNIGHT
📋
Stalker Taurus
📋
TELLURIUM
📋
TICK CASTLE
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD