TIDRONE — APT Profile
TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers in Taiwan. The actor employs advanced malware variants such as CXCLNT and CLNTEND, which are distributed through ERP software or remote desktops. The consistency in file compilation times and operational patterns aligns with other Chinese espionage activities, indicating a likely espionage motive.Also tracked as
Earth Ammit, Operation WordDrone
Tools & malware
- CLNTEND RAT
- CXCLNT Backdoor
- SCREENCAP Tool
- TrueSightKiller Tool
- VENFRPC Tool
Vendor research
- TIDRONE Targets Military and Satellite Industries in Taiwan Trend Micro
- Earth Ammit Disrupts Drone Supply Chains Through Coordinated Multi-Wave Attacks in Taiwan Trend Micro
- Operation WordDrone: How Drone manufacturers are being targeted in Taiwan Acronis
- Analysis on the Case of TIDRONE Threat Actor's Attacks on Korean Companies AhnLab Security Intelligence Center (ASEC)
- TIDRONE Espionage Group Targets Taiwan Drone Makers in Cyber Campaign The Hacker News
- Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE Campaigns The Hacker News
Countries linked to this actor
- Taiwan targets