Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Taidoor

Also known as: G0015, Earth Aughisky

Description

The Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Taiwanese IP addresses as C&C servers and email addresses to send out socially engineered emails with malware as attachments. One of the primary targets of the Taidoor campaign appeared to be the Taiwanese government. The attackers spoofed Taiwanese government email addresses to send out socially engineered emails in the Chinese language that typically leveraged Taiwan-themed issues. The attackers actively sent out malicious documents and maintained several IP addresses for command and control. As part of their social engineering ploy, the Taidoor attackers attach a decoy document to their emails that, when opened, displays the contents of a legitimate document but executes a malicious payload in the background. We were only able to gather a limited amount of information regarding the Taidoor attackers’ activities after they have compromised a target. We did, however, find that the Taidoor malware allowed attackers to operate an interactive shell on compromised computers and to upload and download files. In order to determine the operational capabilities of the attackers behind the Taidoor campaign, we monitored a compromised honeypot. The attackers issued out some basic commands in an attempt to map out the extent of the network compromise but quickly realized that the honeypot was not an intended targeted and so promptly disabled the Taidoor malware running on it. This indicated that while Taidoor malware were more widely distributed compared with those tied to other targeted campaigns, the attackers could quickly assess their targets and distinguish these from inadvertently compromised computers and honeypots.

AI Analysis

· 1 week ago

Executive Summary

The Taidoor threat actor has been conducting targeted cyberattacks since at least 2009, primarily focusing on the Taiwanese government through socially engineered emails and malware. Their campaigns often use Taiwanese IP addresses for command and control (C2) servers, and their activities suggest a mix of political and potential state-sponsored motivations.

Goals & Targeting

The Taidoor threat actors appear to target sectors aligned with political or governmental interests in Taiwan and regions with similar thematic issues. Their focus on government entities suggests possible motivations aligned with intelligence gathering, regime change, or undermining trust in local institutions. The group's ability to tailor attacks for specific languages and themes indicates a strategic targeting approach likely directed at organizations where the impact would be maximized.

Enhanced Description

The Taidoor attackers are known to conduct targeted attacks leveraging social engineering tactics, sending malicious emails in Chinese that appear to originate from Taiwanese government sources. These emails often include decoy documents designed to mimic legitimate content while executing malicious payloads in the background. The group primarily targets sectors related to politics and governance, suggesting a focus on influencing or gathering information from specific regions or institutions. Despite their operations starting as early as 2009, there is limited visibility into their post-compromise activities, indicating they may prioritize precision over extensive lateral movement within networks. Their use of tailored social engineering and regional targeting highlights a strategic approach to attack selection.

Key Capabilities

  • Social engineering through spear-phishing emails
  • Deployment of malicious documents as decoy payloads
  • Use of command-line shell tools for post-exploitation
  • Operational capability to assess compromised networks and distinguish legitimate targets from honeypots

MITRE ATT&CK Tactics

Initial Access
Execution

ATT&CK Techniques

T1057
T1064.002

Software / Tooling

Custom malicious document payloads
Command-line shell tools for C2

Campaigns & Victims

The Taidoor campaign has demonstrated significant longevity, with activity traced back to at least 2009. Their campaigns appear to balance targeted attacks on government entities with broader distribution attempts that include social engineering on a national scale. A notable pattern is the use of themes relevant to Taiwan and Chinese-speaking regions, targeting individuals or groups with potential ties to these areas. Campaigns often start with spear-phishing emails, though post-exploitation behavior appears limited unless targets align closely with their interests.

IOC Patterns

  • Spear phishing emails in Chinese with Taiwanese government-themed content
  • Malicious document payloads attached to seemingly legitimate emails
  • Command and control traffic originating from Taiwanese IP addresses

Recommended Actions

  • Implement robust email filtering to detect and block suspicious messages mimicking known government sources.
  • Monitor network traffic for anomalies, especially from known compromised regions or sectors.
  • Conduct regular training sessions on social engineering awareness among employees.
  • Segment networks to limit lateral movement in the event of a breach.

Suggested Tags

APT
Political Motivation
Taiwan/China Region

Confidence Assessment

The available information on Taidoor is limited, particularly regarding their long-term goals and exact targeting criteria. While the group's social engineering methods and regional focus are well-documented, there is lower confidence in their broader operational patterns or potential affiliations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Government Targeting
APT
Political Motivation
Taiwan/China Region

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.