Also known as: G0015, Earth Aughisky
The Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Taiwanese IP addresses as C&C servers and email addresses to send out socially engineered emails with malware as attachments. One of the primary targets of the Taidoor campaign appeared to be the Taiwanese government. The attackers spoofed Taiwanese government email addresses to send out socially engineered emails in the Chinese language that typically leveraged Taiwan-themed issues. The attackers actively sent out malicious documents and maintained several IP addresses for command and control. As part of their social engineering ploy, the Taidoor attackers attach a decoy document to their emails that, when opened, displays the contents of a legitimate document but executes a malicious payload in the background. We were only able to gather a limited amount of information regarding the Taidoor attackers’ activities after they have compromised a target. We did, however, find that the Taidoor malware allowed attackers to operate an interactive shell on compromised computers and to upload and download files. In order to determine the operational capabilities of the attackers behind the Taidoor campaign, we monitored a compromised honeypot. The attackers issued out some basic commands in an attempt to map out the extent of the network compromise but quickly realized that the honeypot was not an intended targeted and so promptly disabled the Taidoor malware running on it. This indicated that while Taidoor malware were more widely distributed compared with those tied to other targeted campaigns, the attackers could quickly assess their targets and distinguish these from inadvertently compromised computers and honeypots.
Executive Summary
The Taidoor threat actor has been conducting targeted cyberattacks since at least 2009, primarily focusing on the Taiwanese government through socially engineered emails and malware. Their campaigns often use Taiwanese IP addresses for command and control (C2) servers, and their activities suggest a mix of political and potential state-sponsored motivations.
Goals & Targeting
The Taidoor threat actors appear to target sectors aligned with political or governmental interests in Taiwan and regions with similar thematic issues. Their focus on government entities suggests possible motivations aligned with intelligence gathering, regime change, or undermining trust in local institutions. The group's ability to tailor attacks for specific languages and themes indicates a strategic targeting approach likely directed at organizations where the impact would be maximized.
Enhanced Description
The Taidoor attackers are known to conduct targeted attacks leveraging social engineering tactics, sending malicious emails in Chinese that appear to originate from Taiwanese government sources. These emails often include decoy documents designed to mimic legitimate content while executing malicious payloads in the background. The group primarily targets sectors related to politics and governance, suggesting a focus on influencing or gathering information from specific regions or institutions. Despite their operations starting as early as 2009, there is limited visibility into their post-compromise activities, indicating they may prioritize precision over extensive lateral movement within networks. Their use of tailored social engineering and regional targeting highlights a strategic approach to attack selection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Taidoor campaign has demonstrated significant longevity, with activity traced back to at least 2009. Their campaigns appear to balance targeted attacks on government entities with broader distribution attempts that include social engineering on a national scale. A notable pattern is the use of themes relevant to Taiwan and Chinese-speaking regions, targeting individuals or groups with potential ties to these areas. Campaigns often start with spear-phishing emails, though post-exploitation behavior appears limited unless targets align closely with their interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information on Taidoor is limited, particularly regarding their long-term goals and exact targeting criteria. While the group's social engineering methods and regional focus are well-documented, there is lower confidence in their broader operational patterns or potential affiliations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics