logo

Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies | Symantec Blogs

ID: 0ca96a4c-557d-4f6b-963f-081a4b37670c

STIX ID: report--0ca96a4c-557d-4f6b-963f-081a4b37670c

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2018-06-21

Last Modified Date: 2018-06-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details a targeted cyber-espionage campaign attributed to the Thrip group, using living-off-the-land techniques and a mix of custom malware and off-the-shelf tools to compromise satellite communications, geospatial imaging, telecoms, and a defense contractor across the United States and Southeast Asia. The investigation highlights PsExec and PowerShell for lateral movement, multiple Trojan and info-stealer families (Rikamanu, Catchamas, Mycil, Spedear, Syndicasec), and the role of Symantec's Targeted Attack Analytics in detecting the activity.