Thrip

G0076

Threat group.View on attack.mitre.org

About this group

Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as "living off the land" techniques.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP.

T1059.001
PowerShell

Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance.

T1219.002
Remote Desktop Software

Thrip used a cloud-based remote access software called LogMeIn for their attacks.

T1588.002
Tool

Thrip has obtained and used tools such as Mimikatz and PsExec.

Software3

Campaigns0

None recorded.

References1

  1. Symantec Thrip June 2018 Open source
    Security Response Attack Investigation Team. (2018, June 19). Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies. Retrieved July 10, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.