Symantec-tracked cyberespionage group using Dripion malware to target diplomatic and government entities.
Analyst brief
Budminer is an advanced cyberespionage group attributed by Symantec to campaigns involving the Dripion malware. The group has historically targeted government entities and diplomatic organizations, but has shifted tactics following public exposure. Key TTPs include the use of Dripion trojan, likely initial access via compromised websites, and altered C2 infrastructure; their older Taidoor malware has not been seen in new campaigns since 2014. Defenders should focus on detecting anomalous network traffic, especially unusual C2 communications, and avoid relying solely on signatures for legacy tools.
Budminer
Budminer cyberespionage group
unknown
Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group. While we have not seen newcampaigns using Taidoor malware since 2014, we believe the Budminer group has changedtactics to avoid detection after being outed publicly in security white papers and blogs over thepast few years.