A sophisticated cyber espionage operation linked to Chinese-speaking nation-state actors has been conducting targeted campaigns against critical sectors in Taiwan and South Korea. Security researchers at Trend Micro have identified two related campaigns—VENOM and TIDRONE—operating between 2023 and 2024.
## Dual Campaign Strategy
The threat actor, known as Earth Ammit, has strategically targeted multiple sectors including military, satellite, heavy industry, media, technology, software services, and healthcare. The VENOM campaign primarily focused on software service providers, while TIDRONE specifically targeted military industry entities.
“Earth Ammit’s approach involved penetrating the upstream segment of the drone supply chain,” explained Trend Micro researchers. “Their long-term goal is to compromise trusted networks via supply chain attacks, allowing them to target high-value entities downstream.”
## Attack Methodology
The attacks are notable for their strategic targeting of drone supply chains and exploitation of enterprise resource planning (ERP) software to breach military and satellite industries. The threat actors have also leveraged trusted communication channels, including remote monitoring and IT management tools, to distribute malicious payloads.
The VENOM campaign exploits web server vulnerabilities to deploy web shells, followed by remote access tools (RATs) for persistent access. The attackers deliberately use open-source tools like REVSOCK and Sliver to obscure attribution, with VENFRPC—a customized version of the open-source fast reverse proxy tool—being the only custom malware observed.
## TIDRONE Campaign Structure
The TIDRONE campaign operates in three distinct phases:
1. **Initial Access**: Mirrors VENOM by targeting service providers to inject malicious code for distribution to downstream customers
2. **Command-and-Control**: Employs a DLL loader to deploy CXCLNT and CLNTEND backdoors
3. **Post-Exploitation**: Establishes persistence, escalates privileges, disables antivirus using TrueSightKiller, and installs SCREENCAP for surveillance
The CXCLNT backdoor, active since at least 2022, uses a modular plugin system that “retrieves additional plugins from its C&C server to extend its capabilities dynamically.” Its 2024 successor, CLNTEND, features enhanced detection evasion capabilities.
## Connection to Chinese Threat Actors
Researchers have identified connections between Earth Ammit and another Chinese nation-state hacking group known as Dalbit (m00nlight) based on similar tactics, techniques, and procedures.
“This progression underscores a deliberate strategy: start broad with low-cost, low-risk tools to establish access, then pivot to tailored capabilities for more targeted and impactful intrusions,” noted Trend Micro researchers.
## Swan Vector Campaign
In a separate but related development, Seqrite Labs has uncovered a cyber espionage campaign called Swan Vector targeting educational institutions and mechanical engineering companies in Taiwan and Japan. This operation uses fake resume lures in spear-phishing emails to deliver a DLL implant called Pterois, which subsequently downloads Isurus malware and Cobalt Strike shellcode.
The Swan Vector campaign, attributed to an East Asian threat actor active since December 2024, employs multiple evasion techniques including API hashing, direct-syscalls, function callbacks, DLL side-loading, and self-deletion to avoid detection.
