Bronze Butler is a apt_group tracked across 8 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity May 4, 2026.
Bronze Butler is a China-linked APT group engaged in cyber espionage campaigns, targeting diplomatic and governmental entities. The group is associated with use of zero-day exploits and targeted operations, including activities against European diplomats, highlighting its role in state-sponsored cyber campaigns and its evolving tactic profile.
China-linked cyber-espionage group Bronze Butler, also known as Tick, exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
A China-linked hacking group, UNC6384, has exploited a Windows zero-day vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks, which occurred in…
Cyber-espionage group Bronze Butler, also known as Tick, has exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw was used…
Chinese state-affiliated hackers, identified as UNC6384, have exploited a Windows zero-day vulnerability (CVE-2025-9491) to conduct cyber espionage against European diplomats in countries such as Belgium and Hungary.…
In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of…
CYFIRMA Research and Advisory Team has identified Bactor Ransomware while monitoring underground forums. This ransomware targets Windows systems and affects multiple industries and technologies. The findings are part of…
Multiple ransomware strains, including Bactor, ChickenKiller, and Midnight, have been identified by CYFIRMA Research and Norton. Bactor and ChickenKiller ransomware target Windows systems, while Midnight ransomware has…