Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE Campaigns

Two similar but separate efforts from 2023 to 2024 targeting different groups in Taiwan and South Korea, including the military, satellite, heavy industry, media, technology, software services, and healthcare sectors, have been linked to a cyber espionage group called Earth Ammit.

According to cybersecurity company Trend Micro, the second wave, known as TIDRONE, specifically targeted the military sector, while the first wave, codenamed VENOM, mostly targeted software service providers. According to assessments, Earth Ammit is associated with nation-state organizations that speak Chinese.

Security researchers Pierre Lee, Vickie Su, and Philip Chen stated that Earth Ammit’s strategy for its VENOM campaign was to infiltrate the upstream portion of the drone supply chain. In order to target high-value businesses downstream and expand their reach, Earth Ammit’s long-term objective is to breach trusted networks through supply chain attacks.

Last year, Trend Micro initially revealed the TIDRONE campaign, which described how the cluster targeted Taiwanese drone manufacturers to spread custom malware read more about Earth Ammit Breached Drone Supply Chains via ERP in VENOM TIDRONE Campaigns.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *