Taidoor
Also reported as Budminer, Earth Aughisky and Budminer cyberespionage group. Linked to China by three sources.
Reports per quarter
CVEs named in reports
- CVE-2009-1129
- CVE-2009-3129 KEV
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-1297 KEV
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-1269
- CVE-2011-12696
- CVE-2011-2100
Show all 71 CVEs Show fewer
- CVE-2011-2462 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0507 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1889 KEV
- CVE-2012-2543
- CVE-2013-0640 KEV
- CVE-2013-2729 KEV
- CVE-2013-3893 KEV
- CVE-2013-5990
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-6332 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-8759 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-4939 KEV
- CVE-2018-6789 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-1040
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-9489
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-15505 KEV
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8515 KEV
- CVE-2021-30116 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
-
The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unveiling the CryptoMimic
-
Taidoor - a truly persistent threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taidoor - a truly persistent threat
Show all 31 reports Show fewer
-
MAR-10292089-1.v2 – Chinese Remote Access Trojan_ TAIDOOR _ CISA
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MAR-10292089-1.v2 – Chinese Remote Access Trojan_ TAIDOOR _ CISA
-
MAR-10292089-1.v1 – Chinese Remote Access Trojan- TAIDOOR
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MAR-10292089-1.v1 – Chinese Remote Access Trojan- TAIDOOR
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PoshC2_APT_jp
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor taidoor_analysis_jp
-
Taiwan targeted with new cyberespionage back door Trojan
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Taiwan targeted with new cyberespionage back door Trojan
-
Evasive Tactics: Taidoor « Threat Research | FireEye Inc
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Evasive Tactics: Taidoor « Threat Research | FireEye Inc
-
The original link failed its last check. Original publisher Detailsfor 1408.1136.pdf
-
2Q Report on Targeted Attack Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2Q Report on Targeted Attack Campaigns
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evasive Tactics- Taidoor
-
The Taidoor Campaign: An In-Depth Analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Taidoor Campaign: An In-Depth Analysis
-
Trojan.Taidoor: Targeting Think Tanks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Trojan.Taidoor: Targeting Think Tanks
-
Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI)
Newest first. Details opens the report in Explore.