Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TIDRONE

Also known as: Earth Ammit, VENOM, APT28, Fancy Bear, Asylum Ambuscade, Paper Werewolf, Sofacy, Pawn Storm, Sednit, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Guildma, UNC4221, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, RedMike, OPERATOR PANDA

Description

TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers in Taiwan. The actor employs advanced malware variants such as CXCLNT and CLNTEND, which are distributed through ERP software or remote desktops. The consistency in file compilation times and operational patterns aligns with other Chinese espionage activities, indicating a likely espionage motive.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Manufacturing
Government
Aerospace
Telecommunications
Energy
Transportation
Media
Healthcare
Education
Construction
Critical infrastructure
Pharmaceutical
Retail
Utilities
Non profit
Information technology
Food agriculture
Chemical
Aviation
Maritime
Mining
Nuclear
Oil gas

Targeted Countries / Regions

TW
RU
KR
CN
UA
IN
TR
US
CA
PK
DE
JP
AE
VN
BR
IR
IT
SA
AU
IL
FR

AI Analysis

· 1 week ago

Executive Summary

TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, focusing on military-related industries in Taiwan. The actor employs advanced malware (CXCLNT, CLNTEND) distributed via ERP software or remote desktops, suggesting espionage motives.

Goals & Targeting

TIDRONE's strategic objectives appear to be espionage-related, targeting military supply chains and defense industries. Their focus on Taiwan suggests a geopolitical angle, potentially linked to broader Chinese interests in regional security and technology acquisition.

Enhanced Description

TIDRONE is a sophisticated cyber威胁actor of unknown origin but associated with Chinese-speaking groups. The actor primarily targets military-related industries, particularly drone manufacturers in Taiwan. TIDRONE's methods indicate high-level capabilities and likely state-sponsored activity due to the focus on sensitive sectors and alignment with espionage patterns observed in other Chinese-linked actors. The use of advanced malware variants (CXCLNT, CLNTEND) highlights technical expertise.

Key Capabilities

  • Advanced malware development
  • Remot access exploitation
  • Malware distribution via software supply chain

MITRE ATT&CK Tactics

Adversary Persistance
Exfiltration
Credential Access

ATT&CK Techniques

T1059
T1214
T1566.001

Software / Tooling

CXCLNT
CLNTEND
Custom Ransomware

Campaigns & Victims

Campaign patterns suggest patient, targeted operations focusing on military and defense sectors. Limited data available on specific campaigns linked to TIDRONE.

IOC Patterns

  • S Spear phishing with ERP software payloads
  • C2 communication via remote desktop protocols

Recommended Actions

  • Monitor RDP access for unusual activity.
  • Secure supply chains by validating software updates.
  • Implement training programs against spear-phishing.

Suggested Tags

APT
military Espionage
China-linked threat actor

Confidence Assessment

High confidence in TIDRONE's Chinese linkages and espionage focus, but limited data on specific campaigns and tools.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 12 Domain 7 SHA-256 Hash 1

References

  1. ics-cert.kaspersky.com — Cited by web research for: Sofacy
  2. ics-cert.kaspersky.com — Cited by web research for: APT-C-35
  3. attack.mitre.org — Cited by web research for: T1548
  4. www.trendmicro.com — Cited by web research for: Payload
  5. www.trendmicro.com — Cited by web research for: Trojan
  6. apt.etda.or.th — Cited by web research for: MuddyWater

Intel Summary

40

Techniques

40

Tools

0

Campaigns

43

IOCs

0

Observed Data

13

Tactics

Tags

APT
Government Targeting
military Espionage
China-linked threat actor

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.