Threat group.View on attack.mitre.org
Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as "living off the land" techniques.
| Technique | Procedure example |
|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP. |
| T1059.001 PowerShell |
Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance. |
| T1219.002 Remote Desktop Software |
Thrip used a cloud-based remote access software called LogMeIn for their attacks. |
| T1588.002 Tool |
Thrip has obtained and used tools such as Mimikatz and PsExec. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.