Earth Ammit
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: TIDRONE, VENOM
Earth Ammit is a Chinese-speaking advanced persistent threat group that first emerged with documented activity in 2022, primarily engaging in long-term cyberespionage. The group gained notoriety for its coordinated multi-wave supply chain attacks, notably the VENOM campaign (2023-2024) which leveraged open-source tools against service providers, and the TIDRONE campaign (2024) which deployed custom backdoors against military and satellite sectors. Earth Ammit's core motivation is espionage, targeting sensitive defense supply chains in countries like Taiwan and South Korea to exfiltrate critical data. What sets this group apart is its strategic evolution from low-cost, open-source tooling to proprietary, in-memory backdoors with modular plugins, alongside a distinctive reliance on fiber-based execution techniques to evade detection.