The Drone Supply Chain's Grand Siege: From Initial Breaches to Long-Term Espionage
Black Hat Asia 2025 · Day 1 · Briefings
Overview
This talk, "The Drone Supply Chain's Grand Siege: From Initial Breaches to Long-Term Espionage on High Value Targets," delivered by Trend Micro's Vicki Sue and Philip Chen, uncovers a sophisticated and multi-stage supply chain attack orchestrated by the advanced persistent threat (APT) group dubbed Earth Hammet. The research details two interconnected campaigns, Campaign Venom and Campaign Ty-Drone, which systematically targeted the drone industry and its related upstream service providers, primarily in Taiwan and South Korea. The speakers reveal how initial breaches into less secure upstream vendors were leveraged to gain access to high-value downstream targets, including military, satellite, and payment services.

Key moments
- 0:00 Talk introduction and speakers
- 2:30 Research origin: Drone supply chain attacks
- 3:20 Why the drone industry is a high-value target
- 4:10 Campaign Hydrone: Victims and customized tools
- 5:35 Campaign Venom: Diverse victims, open-source tools
- 6:45 Attacker's view: Classic vs. general supply chain attacks
- 8:00 Earth Hammet's grand timeline connecting campaigns
The Drone Supply Chain's Grand Siege: From Initial Breaches to Long-Term Espionage
Speakers: Vicki Sue, Senior Threat Researcher, Trend Micro; Philip Chen, Threat Researcher, Trend Micro
Conference: Black Hat Asia
YouTube: https://www.youtube.com/watch?v=c9SAHP92niA
Overview
This talk, "The Drone Supply Chain's Grand Siege: From Initial Breaches to Long-Term Espionage on High Value Targets," delivered by Trend Micro's Vicki Sue and Philip Chen, uncovers a sophisticated and multi-stage supply chain attack orchestrated by the advanced persistent threat (APT) group dubbed Earth Hammet. The research details two interconnected campaigns, Campaign Venom and Campaign Ty-Drone, which systematically targeted the drone industry and its related upstream service providers, primarily in Taiwan and South Korea. The speakers reveal how initial breaches into less secure upstream vendors were leveraged to gain access to high-value downstream targets, including military, satellite, and payment services.
The significance of this research lies in its exposure of a meticulously planned and executed espionage operation against a critical and rapidly growing industry. The drone sector, with its deep connections to government, military, and critical infrastructure, represents an extremely valuable target for nation-state actors seeking long-term intelligence gathering and strategic advantage. The findings highlight the evolving tactics of APT groups, including their adept use of both widely available open-source tools and highly customized, evasive malware, along with their diligent adoption of cutting-edge anti-analysis techniques presented at major security conferences.
By dissecting the infection chains, malware analysis, and attribution indicators, Trend Micro provides a comprehensive view of Earth Hammet's operational security and strategic objectives. The talk serves as a critical warning to organizations within high-value supply chains, emphasizing the need for robust security measures that extend beyond direct protection to include the entire ecosystem of trusted partners and service providers. It underscores the continuous arms race between attackers and defenders, where threat actors rapidly integrate novel evasion techniques to maintain stealth and achieve their espionage goals.
Background
▶ Watch: Talk introduction and speakers (0:00)
The genesis of this research stemmed from a series of cybersecurity incidents reported by several companies in Taiwan, which Trend Micro observed to be highly overlapped with public news reports. Upon tracing back the compromised entities, a crucial link emerged: all victimized companies were connected to the same upstream service provider. This strong correlation immediately suggested the possibility of a supply chain attack, prompting Trend Micro to initiate a deeper investigation.
The drone industry has rapidly ascended in strategic importance, making it a prime target for sophisticated threat actors. From a military and security perspective, drones offer invaluable support in defense, surveillance, and disaster response, significantly enhancing operational efficiency and safety. Economically, the industry is experiencing explosive growth, particularly in Taiwan, where a 50-member Taiwanese drone supply chain alliance has been launched with government backing. This alliance aims to produce 15,000 drones monthly and achieve an industrial output of NT30 billion (approximately USD 1 billion) by 2028, underscoring the deep and sensitive connections between the drone industry and governmental interests.
The investigation uncovered two distinct yet interconnected campaigns: Campaign Venom and Campaign Ty-Drone, both attributed to the Earth Hammet intrusion set. The speakers clarified that their research initially identified Campaign Ty-Drone, followed by Campaign Venom, but the attacker's strategy suggested Venom preceded Ty-Drone in the overall attack timeline. Campaign Venom primarily targeted upstream entities, including heavy industry, media, technology, software service providers, and healthcare industries in Taiwan and South Korea, from 2023 to 2024. Its arsenal heavily relied on open-source tools to maintain a low profile. In contrast, Campaign Ty-Drone, active in 2024, focused on downstream, high-value targets such as satellite vendors, drone vendors, military-related vendors, and payment services in Taiwan and South Korea, utilizing more customized tools. The earliest traces of Earth Hammet's activities, including samples submitted to VirusTotal from Korea and Canada, date back to 2022.
Earth Hammet's strategic approach involved a two-pronged supply chain attack model. The classic model, involving malicious code injection or replacing legitimate updates, was observed. However, the group also employed a "general supply chain attack" method, where they penetrated trusted channels, such as monitoring or remote management tools, to distribute malware to downstream customers. The connection between Campaign Venom and Campaign Ty-Drone was established through two strong indicators: shared victimology and service providers across both campaigns, and overlapping command-and-control (C2) infrastructure, exemplified by the domain fword-everyday.life. This meticulously planned strategy highlights Earth Hammet's intent to compromise the drone supply chain's upstream to subsequently exert widespread impact on downstream, high-value targets.
Key Findings
▶ Watch: Why the drone industry is a high-value target (3:20)
The research unveiled several critical findings regarding the Earth Hammet intrusion set and its campaigns against the drone supply chain:
- Two-Tiered Supply Chain Attack Strategy: Earth Hammet executed a sophisticated, multi-stage supply chain attack model. Campaign Venom focused on compromising upstream service providers and technology companies, often using open-source tools to establish a foothold and steal credentials like NTDS data. This initial phase served as a launchpad for Campaign Ty-Drone, which then leveraged the compromised upstream access to target high-value downstream entities directly involved in the drone, military, and satellite industries with more customized malware. This "test the waters" strategy, starting with common tools before escalating to advanced ones, demonstrates a careful and calculated approach to maximize impact while minimizing early detection.
- Rapid Adoption of Advanced Evasion Techniques: A significant discovery was Earth Hammet's diligent and rapid integration of cutting-edge evasion techniques into their malware loaders. The speakers highlighted the adoption of fiber-based techniques in 2023 and an evolved fiber-based technique in 2024, followed by exception handling mechanisms, all of which appeared around the same time they were presented at prominent Black Hat conferences. This indicates a highly adaptive adversary that actively monitors the cybersecurity landscape for novel methods to bypass security products, particularly those that primarily monitor system threads rather than application-level execution.
- Hybrid Malware Arsenal: Earth Hammet employs a diverse arsenal, blending readily available open-source tools with proprietary, customized malware. Campaign Venom predominantly utilized open-source proxy tools and open-source RATs (Remote Access Trojans) to obscure their footprint, while Campaign Ty-Drone deployed custom backdoors like CX Client and Client End, alongside specialized tools such as Screen Cap and anti-AV utilities like True Sight Killer. This hybrid approach allows the attackers to achieve initial access and maintain stealth with less attributable tools, before deploying more potent and tailored malware against specific high-value targets.
- Strategic Targeting of High-Value Industries: The victimology across both campaigns clearly indicates a strategic focus on entities critical to national security and economic interests. Targets included satellite vendors, drone manufacturers, military contractors, and payment services, all of which are deeply intertwined with governmental operations and sensitive data. The scale of the Taiwanese drone alliance, with its ambitious production and economic targets, underscores why this sector is a prime target for long-term espionage.
- Attribution to Chinese-Speaking Actor: While specific group names were not definitively assigned, attribution indicators strongly suggest a Chinese-speaking actor. This assessment is based on file compilation and command execution times observed in C2 communication logs, consistently aligning with the GMT+8 time zone. Furthermore, the observed Tactics, Techniques, and Procedures (TTPs) and target scope bore similarities to another well-known attack group, "Earthworm," as introduced by Naver, reinforcing the profile of a sophisticated, likely state-sponsored, actor.
Technical Deep Dive
▶ Watch: Campaign Hydrone: Victims and customized tools (4:10)
The technical deep dive into Earth Hammet's operations reveals a meticulous, multi-stage attack architecture, leveraging both generic and highly specific tools across Campaign Venom and Campaign Ty-Drone.
Campaign Venom Infection Chain
Campaign Venom primarily targeted upstream service providers and industries, acting as the initial breach point for Earth Hammet.
- Initial Access: Attackers typically exploited vulnerabilities in web servers, deploying web shells to gain initial control. This is described as a common, yet effective, method.
- Command and Control (C2): Once inside, the attackers focused on establishing persistence and C2 using a variety of open-source proxy tools and open-source RATs. This deliberate choice of readily available tools aimed to minimize the attacker's footprint and make attribution more challenging.
- Credential Stealing: A critical objective in this phase was the theft of NTDS data. The speakers showed a figure of real, albeit redacted, NTDS data, emphasizing its importance in compromising downstream customers – the next stage of the attack, represented by Campaign Ty-Drone.
Campaign Ty-Drone Infection Chain
Building upon the success of Campaign Venom, Campaign Ty-Drone then targeted the high-value downstream entities.
- Initial Access: This phase leveraged the compromised upstream providers from Campaign Venom. Attackers performed malicious code injection and distributed malware through trusted channels, such as remote management or monitoring tools, exploiting the inherent trust between upstream and downstream entities.
- Command and Control (C2): Unlike Venom, Ty-Drone extensively utilized customized malware for C2. Two primary backdoors were identified:
- CX Client (Version A): This backdoor's loader relied on two separate files: a payload file and a configuration file.
- Client End (Version B): An evolved version where the loader depended on a single payload file with an embedded configuration. This variation was likely designed to decrease detection by security products looking for multi-file dependencies.
- Post-Exploitation: Once C2 was established, the attackers used the remote shell capabilities within Client End to execute various post-exploitation behaviors:
- Privilege Escalation: Techniques included UAC bypassing and attempts to restart processes with a privileged token.
- Persistence: Achieved by creating scheduled tasks and, more stealthily, by replacing legitimate executables in selected directories with malicious versions.
- Credential Dumping: Attackers performed process dumps for lsass.exe and utilized tools like
cmdp.exeand Mimikatz to extract credentials. - Information Collection: A customized tool named Screen Cap, disguised as
man.exe, was installed by Client End via its remote shell to steal screenshots from victims. This tool was adapted from an open-source GitHub repository (github.com/616/ScreenCapture). - Disabling AV: The attackers deployed an AVR killer called True Sight Killer, designed to terminate various anti-virus and EDR processes, allowing them to bypass security measures and operate unimpeded.
Malware Analysis
The speakers provided a detailed breakdown of the key malware components:
- BF FRPC (Campaign Venom):
- This tool is a modified version of FRP (Fast Reverse Proxy), an open-source tool that makes internal services accessible from the internet.
- The configuration is directly embedded within the binary, containing victim identification details to help attackers recognize their targets.
- Interestingly, the attackers hosted their modified BF FRPC versions on their own GitHub repository, with each binary containing a unique configuration for different targets.
- CX Client / Client End Loaders (Campaign Ty-Drone):
- Trend Micro observed a clear evolution in the loaders' evasion techniques:
- 2023: Initial fiber-based technique using
ConvertThreadToFiber,CreateFiber, andSwitchToFiber.ConvertThreadToFiberconverts the current thread into a fiber, allowing it to switch execution to new fibers created byCreateFiber, where the malicious code is placed (at fiber structure + C4 in hex).SwitchToFiberthen executes this malicious code. - 2024 (Early): A new fiber-based technique emerged, leveraging
FlsAllocandRegisterFiberObject. Here, a callback function registered withRegisterFiberObjectis triggered upon object deallocation or deletion, executing the malicious code. - 2024 (Later): An exception handling technique appeared, where malicious code is executed within a custom exception handler when a specific exception is triggered.
- The speakers highlighted that these fiber-based techniques were presented at Black Hat USA 2023 and Black Hat Asia 2024 by Daniel Jerry, suggesting the attackers diligently follow industry trends.
- Fiber vs. Thread: Fibers are managed by the application, making them less detectable by security products that primarily monitor OS-managed system threads. This is a key reason for their increasing use in malware.
- Anti-Analysis Techniques: Loaders incorporated checks like
GetModuleHandleto retrieve process information and XOR it with specific bytes, failing if the entry point doesn't match the expected target process. Another technique involved distributing decryption and payload execution across multiple functions, requiring a precise execution order to avoid analysis failure or getting stuck.
- CX Client Backdoor (Campaign Ty-Drone):
- Traced back to 2022, this backdoor operates entirely in memory, without dropping files to disk.
- Network traffic supports SSL with a custom protocol and HTTPS.
- Its main functionality is dependent on a plugin received from the C2, making direct analysis difficult.
- Communication involves a 20-byte traffic header containing command code, two decryption keys (for header and data), an error code, and a victim hash.
- Commands are categorized into "general" (collecting system info, updating config, C2 control) and "plugin" (receiving, starting, getting info about, and stopping plugins). The observed plugin was a DLL with three export functions:
init(start plugin),get_instance(get target folder info), anddelete_instance(stop plugin). - The C2 communication flow involves the victim sending initial info, C2 delivering shellcode/plugin, victim confirming installation, and then C2 leveraging the plugin for specific commands until uninstallation.
- Client End Backdoor (Version 2 of CX Client, Campaign Ty-Drone):
- First discovered in 2024, it also runs memory-resident.
- Supports both client and server modes and multiple connection methods.
- Anti-AV: Employs injection into legitimate host processes (e.g.,
winword.exe) and disabling EDR solutions. The observation of commands executed underwinword.exe(which rarely executescmddirectly) suggests this injection is for evasion or privilege escalation. - Persistence: Offers three methods based on arguments: scheduled tasks, service creation, or no persistence if no arguments are given.
- Commands are divided into "link" (choosing connection methods, alternating modes), "plugin" (similar to CX Client but with two export functions), and "session" (injecting a remote shell into a host process).
- Similarities to CX Client include a function to calculate a victim hash and embedded configuration flags for "testing" (debugging) or "production" modes.
- Screen Cap (Campaign Ty-Drone):
- This is a screen capture tool installed by Client End via its remote shell.
- It sends victim screenshots back to the C2.
- It's adapted from the open-source tool found at
github.com/616/ScreenCapture.
Demo / Proof of Concept
▶ Watch: Attacker's view: Classic vs. general supply chain attacks (6:45)
While the talk did not feature a live demonstration or a real-time proof-of-concept of the attacks in action, the speakers provided detailed technical breakdowns of the malware, including code snippets, configuration formats, and network traffic analysis. They illustrated the structure of C2 traffic headers, the evolution of loader techniques with specific API calls, and the command structures of the backdoors. Examples of .pcap file analysis were shown to demonstrate network flow and communication patterns with the C2 servers, validating their findings through concrete forensic evidence. The depth of the technical analysis served as a compelling "proof-of-concept" for the capabilities of Earth Hammet's tools and techniques.
Defensive Implications
▶ Watch: Earth Hammet's grand timeline connecting campaigns (8:00)
The sophisticated nature of Earth Hammet's campaigns against the drone supply chain demands a multi-faceted and proactive defensive strategy. Organizations, especially those within critical supply chains, must consider the following:
- Comprehensive Supply Chain Security: Defenders must extend their security posture beyond their direct perimeter to encompass all upstream service providers and trusted partners. This involves rigorous vetting, continuous monitoring, and incident response planning that accounts for supply chain attacks originating from trusted channels, not just classic code injection.
- Enhanced Endpoint Detection and Response (EDR) Capabilities: Traditional EDR solutions need to evolve to detect the sophisticated evasion techniques employed by Earth Hammet. This includes:
- Fiber-based Execution Detection: Security products must improve their ability to monitor application-managed fibers, not just OS-managed threads, to catch malware leveraging
ConvertThreadToFiber,CreateFiber,SwitchToFiber,FlsAlloc, andRegisterFiberObject. - Behavioral Monitoring: Detect unusual process injection into legitimate applications (e.g.,
winword.exeexecutingcmd),lsass.exeprocess dumps, and the use of credential dumping tools likemimikatzorcmdp.exe. - Anti-AV/EDR Tool Detection: Implement signatures and behavioral rules to identify and block tools like True Sight Killer that attempt to disable security software.
- Robust Credential Hygiene and Access Control: The theft of NTDS data and other credentials is a primary objective. Organizations must enforce strong password policies, multi-factor authentication (MFA) for all critical systems, regular auditing of privileged accounts, and segmentation of networks to limit lateral movement even if credentials are compromised.
- Network Traffic Analysis and Anomaly Detection: Monitor network traffic for custom SSL protocols, unusual domain names (e.g.,
fword-everyday.life), and C2 communication patterns. The use of open-source proxy tools requires careful monitoring for legitimate proxy usage versus malicious tunneling. - Software Integrity and Patch Management: Regularly patch web servers and other internet-facing applications to prevent exploitation of known vulnerabilities leading to web shell deployment. Implement software integrity checks to detect unauthorized modification or replacement of legitimate executables.
- Threat Intelligence and Proactive Hunting: Stay informed about emerging TTPs, especially those discussed at security conferences, as threat actors are actively adopting them. Proactively hunt for indicators of compromise (IOCs) related to Earth Hammet and similar APT groups, including specific file hashes, C2 domains, and behavioral patterns described in this research.
- Incident Response Preparedness: Develop and regularly test incident response plans that specifically address supply chain attack scenarios. This includes procedures for isolating compromised systems, eradicating malware, restoring affected services, and communicating with affected downstream/upstream partners.
Key Takeaways
- The drone industry, with its critical government and military ties, is a prime target for sophisticated, long-term espionage operations by APT groups like Earth Hammet.
- Supply chain attacks are evolving beyond classic code injection, with attackers leveraging compromised upstream service providers and trusted channels to infiltrate high-value downstream targets.
- Threat actors are rapidly adopting advanced evasion techniques, such as fiber-based execution and exception handling, often gleaned from public security research, to bypass modern security products.
- Earth Hammet employs a strategic blend of readily available open-source tools for initial reconnaissance and footprint reduction, combined with highly customized malware for targeted attacks on specific, high-value victims.
- Comprehensive defense requires a holistic approach, including robust EDR capabilities that can detect novel evasion techniques, stringent credential hygiene, proactive network monitoring, and continuous threat intelligence to anticipate evolving TTPs.
- Organizations within critical supply chains must ensure their security posture extends to all trusted partners and actively monitor for indicators of compromise related to both upstream and downstream attack vectors.
About the Speaker(s)
The talk was presented by Philip Chen and Vicki Sue, both esteemed threat researchers at Trend Micro. Philip Chen, who introduced himself as a junior threat researcher in his second year in the field, demonstrated a keen understanding of the initial phases of the investigation and the broader context of the threat landscape. Vicki Sue, a senior threat researcher with over seven years of experience, delved into the intricate details of malware analysis, loader evolution, and attribution, showcasing her deep expertise.
They are part of a "ninja team" at Trend Micro, dedicated to "saving people's life away from the cyber threat," humorously likening themselves to characters from Naruto. Another key contributor to the research, Pier Lee, was acknowledged but not present at the conference. Together, their combined experience and collaborative effort were instrumental in uncovering the intricate details of Earth Hammet's sophisticated operations against the drone supply chain.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This is a critical piece of threat intelligence, exposing a highly sophisticated, two-tiered supply chain attack by Earth Hammet against the strategically vital drone industry. The research meticulously details how a nation-state actor leveraged upstream breaches to pivot to high-value military, satellite, and payment targets, demonstrating a calculated operational strategy. The most significant takeaway is Earth Hammet's rapid integration of cutting-edge evasion techniques, directly adapting novel fiber-based and exception handling methods presented at recent Black Hat conferences, proving these adversaries are not just watching, but actively incorporating advanced research into their…
Heather Calloway (CISO) — STRONG ACCEPT
This research from Trend Micro provides a critical, actionable analysis of a sophisticated supply chain attack by Earth Hammet targeting the drone industry. The speakers meticulously detail the multi-stage approach, from compromising upstream vendors with open-source tools to leveraging that access for long-term espionage against high-value downstream targets like military and satellite services. The talk excels in identifying the real-world business exposure and the rapid integration of novel evasion techniques by the adversary, offering clear implications for security leaders and defenders.