Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:20:45 UTC APT group: TIDRONE Names TIDRONE (Trend Micro) Country [Unknown] Motivation Information theft and espionage First seen 2024 Description (Trend Micro) Since the beginning of 2024, we have been receiving incident response cases from Taiwan. We track this unidentified threat cluster as TIDRONE. Our research reveals that the threat actors have shown significant interest in military-related industry chains, particularly in the manufacturers of drones. Furthermore, telemetry from VirusTotal indicates that the targeted countries are varied; thus, everyone should stay vigilant of this threat. Observed Sectors: Defense, Telecommunications. Countries: South Korea, Taiwan. Tools used CLNTEND, CXCLNT. Operations performed 2024 Analysis on the Case of TIDRONE Threat Actor’s Attacks on Korean Companies Information Last change to this card: 27 December 2024 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=19ad5f2a-ef83-40b0-a692-fe19702ac6b4 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=19ad5f2a-ef83-40b0-a692-fe19702ac6b4 Page 1 of 1