Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies | Symantec Blogs
ID: 0ca96a4c-557d-4f6b-963f-081a4b37670c
STIX ID: report--0ca96a4c-557d-4f6b-963f-081a4b37670c
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2018-06-21
Last Modified Date: 2018-06-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details a targeted cyber-espionage campaign attributed to the Thrip group, using living-off-the-land techniques and a mix of custom malware and off-the-shelf tools to compromise satellite communications, geospatial imaging, telecoms, and a defense contractor across the United States and Southeast Asia. The investigation highlights PsExec and PowerShell for lateral movement, multiple Trojan and info-stealer families (Rikamanu, Catchamas, Mycil, Spedear, Syndicasec), and the role of Symantec's Targeted Attack Analytics in detecting the activity.
