AVIVORE_reworked_v2.indd
ID: d8fd7309-16ce-420c-a0d0-7b6f72226903
STIX ID: report--d8fd7309-16ce-420c-a0d0-7b6f72226903
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-10-22
Last Modified Date: 2019-10-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Context documents AVIVORE, a suspected nation-state actor (likely Chinese) conducting protracted supply-chain espionage against aerospace, defence and related sectors since at least 2015; the report maps observed TTPs to MITRE ATT&CK, describes use of PlugX implants, living-off-the-land tradecraft, island-hopping via supplier relationships, credential theft and proxying of RDP/SSL VPN traffic, and provides extensive IoCs (hashes, domains, IP ranges, file paths) and mitigations to limit future compromise.
