Uptime Hamster: 11d 0h 18mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Earth Ammit

Earth Ammit

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: TIDRONE, VENOM
Ver en IntelTracker → APTTrail →
Earth Ammit is a Chinese-speaking advanced persistent threat group that first emerged with documented activity in 2022, primarily engaging in long-term cyberespionage. The group gained notoriety for its coordinated multi-wave supply chain attacks, notably the VENOM campaign (2023-2024) which leveraged open-source tools against service providers, and the TIDRONE campaign (2024) which deployed custom backdoors against military and satellite sectors. Earth Ammit's core motivation is espionage, targeting sensitive defense supply chains in countries like Taiwan and South Korea to exfiltrate critical data. What sets this group apart is its strategic evolution from low-cost, open-source tooling to proprietary, in-memory backdoors with modular plugins, alongside a distinctive reliance on fiber-based execution techniques to evade detection.

Aliases del actor

TIDRONEVENOM

Actores similares

apt-earthberberokaactor · 1apt-earthhundunactor · 1apt-earthwendigoactor · 1earthkapreactor · 1Earth Luscaapt · 1earth-berberokaactor · 1earth-kapreactor · 1Earth Wendigoapt · 0Earth Estriesapt · 0Earth Lamiaapt · 0
Motivacion