The China-linked TIDRONE malware gang is targeting drone manufacturers in Taiwan as part of a cyberattack that began in 2024.

Trend Micro is monitoring a competitor called TIDRONE, noting that its activity is related to espionage, as it focuses on industrial chains linked to the military.
See also: ADF soldier accused of spying for Russia
The initial access method used to compromise targets remains unknown at this time. Trend Micro's analysis reveals the development of custom malware, such as CXCLNT and CLNTEND, which leverages remote desktop tools such as UltraVNC.
An interesting common feature observed across multiple victims is the use of the same enterprise resource planning (ERP) software, which increases the likelihood of a supply chain.
Attack chains go through three stages designed to facilitate privilege escalation. These include bypassing User Access Control (UAC), credential dumping, and evading defenses by disabling installed antivirus products on hosts.
Both backdoors are activated through the sideloading of a DLL via the Microsoft Word application, giving threat actors the ability to collect a wide range of sensitive information.
Read also: Microchip Technology: Data breach after cyberattack
CXCLNT has basic file upload and download capabilities, as well as features for cleaning up traces and collecting victim information such as file entries and computer names. It also allows for the download of portable executables (PE) and DLLs for execution at a later stage.
CLNTEND, which was first discovered in April 2024, is a remote access tool (RAT) that supports a wide range of internet protocols for communication, including TCP, HTTP, HTTPS, TLS, and SMB (port 445).

See more: Chinese cyber espionage targets telecom operators in Asia from 2021
"The consistency in file creation times and the duration of the threat actor's operation combined with other Chinese espionage-related activities reinforces the assessment that this campaign is likely being conducted by a previously unknown Chinese-speaking threat group," security researchers Pierre Lee and Vickie Su write.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
