Bronze Butler — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 3, 2025
Last Seen
May 4, 2026

Bronze Butler is a apt_group tracked across 8 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity May 4, 2026.

Overview

Bronze Butler is a China-linked APT group engaged in cyber espionage campaigns, targeting diplomatic and governmental entities. The group is associated with use of zero-day exploits and targeted operations, including activities against European diplomats, highlighting its role in state-sponsored cyber campaigns and its evolving tactic profile.

Related Threat Clusters

Recent Intelligence Reports

  • Threat Actors Automate Zero-Day Discovery with AI | Let's Data Science — Letsdatascience · May 4, 2026
  • T1005 — attack.mitre.org · April 22, 2026
  • T1083 — attack.mitre.org · April 22, 2026
  • Weekly Intelligence Report – 07 November 2025 — Cyfirma · November 6, 2025
  • New China-linked attacks involve zero-day Motex Lanscope bug exploitation — Scworld · November 3, 2025
  • China's Stealthy Zero-Day Strike on European Diplomats Exposed — Webpronews · November 3, 2025

CVSS v3.1 Breakdown