Uptime Hamster: 22d 6h 38mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Earth Ammit

Earth Ammit

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: TIDRONE, VENOM
Ver en IntelTracker → APTTrail →
Earth Ammit is a Chinese-speaking advanced persistent threat group that first emerged with documented activity in 2022, primarily engaging in long-term cyberespionage. The group gained notoriety for its coordinated multi-wave supply chain attacks, notably the VENOM campaign (2023-2024) which leveraged open-source tools against service providers, and the TIDRONE campaign (2024) which deployed custom backdoors against military and satellite sectors. Earth Ammit's core motivation is espionage, targeting sensitive defense supply chains in countries like Taiwan and South Korea to exfiltrate critical data. What sets this group apart is its strategic evolution from low-cost, open-source tooling to proprietary, in-memory backdoors with modular plugins, alongside a distinctive reliance on fiber-based execution techniques to evade detection.

Aliases del actor

TIDRONEVENOM

Actores similares

earth-berberokaactor · 1earth-kapreactor · 1apt-earthberberokaactor · 1apt-earthhundunactor · 1apt-earthwendigoactor · 1earthkapreactor · 1Earth Luscathreat-actor · 1Earth Wendigoapt · 0Earth Estriesapt · 0Earth Lamiaapt · 0
Motivacion