Skip to Content
China icon
China

BRONZE FLEETWOOD

ObjectivesEspionage
AliasesAPT5 (FireEye), DPD (Palo Alto), Keyhole Panda (CrowdStrike), Mulberry Typhoon (Microsoft), Poisoned Flight (Kaspersky), TG-2754 (SCWX CTU)
ToolsBinanen, Comfoo, Gh0st RAT, Isastart, Leouncia, Marade, OrcaRAT, PCShare, Protux, Skeleton Key, SlyPidgin, VinSelf

Summary

BRONZE FLEETWOOD is a threat group that Counter Threat Unit (CTU) researchers assess with moderate confidence operates on behalf of China. The group has previously been observed using both the Leouncia and VinSelf tool kits to target organizations in the aerospace and communications sectors. The intent of the group is likely theft of information from targeted networks. There is strong overlap between the tools and infrastructure used by BRONZE FLEETWOOD and a threat group publicly reported by the CTU dubbed Comfoo.
Threat Bottom Section BG

Contact us

Contact us directly whether your organization needs immediate assistance or
you want to discuss your incident readiness, response, and testing needs.