← Back to all threat actors

Tonto Team

Also known as Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda
Tracked as G0131

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).

How we source and review actor profiles
Motivation
nation-state
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Earth Akhlut

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BRONZE HUNTLEY

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: CactusPete

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Karma Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0131

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Tonto TeamCanonical Name
BRONZE HUNTLEYAlias
CactusPeteAlias
Earth AkhlutAlias
Karma PandaAlias
G0131Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...