logo

'TIDrone' Cyberattackers Target Taiwan's Drone Manufacturers

ID: 3e7cb298-3b96-53a0-b0e5-895d12173816

STIX ID: report--3e7cb298-3b96-53a0-b0e5-895d12173816

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-09

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Trend Micro reports that an advanced Chinese-speaking threat actor named "TIDrone" is actively targeting military and satellite supply chains—particularly drone manufacturers in Taiwan—using ERP and remote desktop access to deploy proprietary RATs (CXCLNT, CLNTEND). The actor employs UAC bypasses, credential dumping, EDR/AV disabling, and anti-analysis techniques, indicating a sophisticated, targeted campaign against critical supply-chain organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.