Thrip

MITRE ATT&CK: G0076 View on attack.mitre.org

Aliases: ATK78, Thrip

First seen
2018-06-20 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 11:49:46

Targeted industries: defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:us country_code:my country_code:ph country_code:th

Context

Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as "living off the land" techniques.

Detection coverage

  • 8 YARA rules
  • 239 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Remote Desktop Software (attack-pattern)
  • Tool (attack-pattern)
  • Catchamas (malware)
  • Mimikatz (malware)
  • PsExec (malware)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • cfr.org — Thrip (report)
  • Broadcom/Symantec — Thrip Hits Satellite Telecoms Defense Targets (report)
  • MITRE ATT&CK — G0076 (report)
  • cyberthreat.thalesgroup.com — Thales%20Threat%20Handbook%202022%20Light%20Version 1 (report)

External references