Budminer

Aliases: Budminer cyberespionage group

First seen
2013-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:58:53

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:us country_code:jp country_code:kr

Context

Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group. While we have not seen newcampaigns using Taidoor malware since 2014, we believe the Budminer group has changedtactics to avoid detection after being outed publicly in security white papers and blogs over thepast few years.

Reports & references

  • Broadcom/Symantec — Taiwan Targeted New Cyberespionage Back Door Trojan (report)
  • app.box.com — Xqh458Fe1Url7Mgl072Hhd0Yxqw3X0Jm (report)
  • research-collection.ethz.ch — Cyber Reports 2020 01 A One Sided Affair (report)

External references