TIDRONE is an espionage threat actor linked to Chinese-speaking groups, targeting military drone manufacturers in Taiwan.
Analyst brief
TIDRONE, also tracked as Earth Ammit and VENOM, is an unidentified threat actor linked to Chinese-speaking groups, primarily conducting espionage. The actor specifically targets military-related industry chains, with a focus on drone manufacturers in Taiwan. Key TTPs involve the deployment of advanced malware variants like CXCLNT and CLNTEND, distributed via ERP software or remote desktop protocols. Defenders should focus on monitoring anomalies within ERP applications and remote access mechanisms, paying close attention to indicators associated with the mentioned malware and unusual file compilation timestamps.
TIDRONE
Earth AmmitVENOM
unknown
TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers in Taiwan. The actor employs advanced malware variants such as CXCLNT and CLNTEND, which are distributed through ERP software or remote desktops. The consistency in file compilation times and operational patterns aligns with other Chinese espionage activities, indicating a likely espionage motive.