logo

AVIVORE_reworked_v2.indd

ID: d8fd7309-16ce-420c-a0d0-7b6f72226903

STIX ID: report--d8fd7309-16ce-420c-a0d0-7b6f72226903

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-10-22

Last Modified Date: 2019-10-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Context documents AVIVORE, a suspected nation-state actor (likely Chinese) conducting protracted supply-chain espionage against aerospace, defence and related sectors since at least 2015; the report maps observed TTPs to MITRE ATT&CK, describes use of PlugX implants, living-off-the-land tradecraft, island-hopping via supplier relationships, credential theft and proxying of RDP/SSL VPN traffic, and provides extensive IoCs (hashes, domains, IP ranges, file paths) and mitigations to limit future compromise.