TIDRONE

Aliases: Earth Ammit, VENOM

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-21 22:56:01
Profile updated
2026-07-07 12:17:09

Targeted industries: defense-and-aerospace manufacturing

Targeted regions: country_code:tw

Context

TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers in Taiwan. The actor employs advanced malware variants such as CXCLNT and CLNTEND, which are distributed through ERP software or remote desktops. The consistency in file compilation times and operational patterns aligns with other Chinese espionage activities, indicating a likely espionage motive.

Reports & references

  • Trend Micro — Tidrone Targets Military And Satellite Industries In Taiwan (report)
  • Trend Micro — Earth Ammit (report)

External references