Also known as: Earth Ammit, VENOM, APT28, Fancy Bear, Asylum Ambuscade, Paper Werewolf, Sofacy, Pawn Storm, Sednit, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Guildma, UNC4221, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, RedMike, OPERATOR PANDA
TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers in Taiwan. The actor employs advanced malware variants such as CXCLNT and CLNTEND, which are distributed through ERP software or remote desktops. The consistency in file compilation times and operational patterns aligns with other Chinese espionage activities, indicating a likely espionage motive.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, focusing on military-related industries in Taiwan. The actor employs advanced malware (CXCLNT, CLNTEND) distributed via ERP software or remote desktops, suggesting espionage motives.
Goals & Targeting
TIDRONE's strategic objectives appear to be espionage-related, targeting military supply chains and defense industries. Their focus on Taiwan suggests a geopolitical angle, potentially linked to broader Chinese interests in regional security and technology acquisition.
Enhanced Description
TIDRONE is a sophisticated cyber威胁actor of unknown origin but associated with Chinese-speaking groups. The actor primarily targets military-related industries, particularly drone manufacturers in Taiwan. TIDRONE's methods indicate high-level capabilities and likely state-sponsored activity due to the focus on sensitive sectors and alignment with espionage patterns observed in other Chinese-linked actors. The use of advanced malware variants (CXCLNT, CLNTEND) highlights technical expertise.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaign patterns suggest patient, targeted operations focusing on military and defense sectors. Limited data available on specific campaigns linked to TIDRONE.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in TIDRONE's Chinese linkages and espionage focus, but limited data on specific campaigns and tools.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
43
IOCs
0
Observed Data
13
Tactics