Earth Ammit is a Chinese state-linked espionage threat actor associated with supply-chain intrusions targeting organizations in East Asia, particularly Taiwan and South Korea. Reporting links the actor to campaigns such as VENOM and TIDRONE, in which it abused enterprise resource planning environments and remote desktop access to deploy backdoors including CXCLNT and CLNTEND, and used tools such as REVSOCK and Sliver for command-and-control and post-compromise operations. Earth Ammit has also been discussed alongside broader Chinese intrusion activity connected to APT41 and UNC4841 in the context of supply-chain attacks. The actor initially drew attention for targeting Taiwanese drone-related supply chains, but subsequent activity showed a broader and more sustained espionage scope. Confirmed victim sectors include heavy industry, media, technology, software services, healthcare, satellite-related organizations, military-adjacent supply chains, and payment service providers in Taiwan and South Korea. This targeting profile indicates an emphasis on strategic industrial and defense-relevant intelligence collection, with particular interest in upstream suppliers and service providers that can provide indirect access to higher-value ecosystems. Observed tradecraft includes supply-chain compromise, abuse of trusted business platforms, use of remote access channels for initial footholds, deployment of custom backdoors, and follow-on use of legitimate offensive-security or remote administration frameworks for persistence and post-exploitation. The actor's operations are consistent with long-term cyber espionage objectives rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber-espionage operations (VENOM and TIDRONE) targeting Taiwan and South Korea, including drone supply-chain related entities, via compromises involving ERP/supply-chain pathways.
Referenced as a China-linked actor associated with supply-chain attacks against satellite operators/ground systems in the space IoT ecosystem.
Two related campaign waves targeting supply chain and military/satellite sectors in Taiwan/South Korea, using web-shelling and credential abuse, open-source tooling, and custom backdoors/proxies.
Earth Ammit is a threat actor specializing in supply chain attacks, targeting upstream vendors to compromise downstream customers across multiple industries in Taiwan and South Korea.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.