Budminer
Aliases: Budminer cyberespionage group
- First seen
- 2013-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:58:53
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:us country_code:jp country_code:kr
Context
Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group. While we have not seen newcampaigns using Taidoor malware since 2014, we believe the Budminer group has changedtactics to avoid detection after being outed publicly in security white papers and blogs over thepast few years.
Reports & references
- Broadcom/Symantec — Taiwan Targeted New Cyberespionage Back Door Trojan (report)
- app.box.com — Xqh458Fe1Url7Mgl072Hhd0Yxqw3X0Jm (report)
- research-collection.ethz.ch — Cyber Reports 2020 01 A One Sided Affair (report)