Thrip

Threat Actor updated 5 months ago (2024-05-04T21:18:23.802Z)
Download STIX
Preview STIX
Thrip, also known as Billbug or Lotus Blossom, is a Chinese-affiliated Advanced Persistent Threat (APT) group that has been active since 2009. The group is primarily focused on espionage activities and targets entities in the communications, geospatial imaging, and defense sectors, both in the United States and Southeast Asia. Thrip's recent operations involved compromising a digital certificate authority in an Asian country, likely using the stolen certificates to sign malware deployed against government agencies over the last six months. The group employs a blend of custom malware such as Infostealer.Catchamas and "living off the land" tactics - using legitimate tools already present on the system for malicious purposes - in their operations. Despite attempts at camouflage, Thrip's cover was blown due to its use of PsExec, a Microsoft Sysinternals tool often used by administrators but also utilized by attackers for lateral movement within networks. This blend of techniques makes Thrip a complex and persistent threat actor, capable of significant cyber-espionage campaigns. Protection against Thrip's activities includes file-based protection, while customers of the DeepSight Intelligence Managed Adversary and Threat Intelligence (MATI) service have received detailed reports on Thrip's methods and how to detect and thwart them. Additionally, the Malware Analysis Appliance can detect activity associated with Thrip. As Thrip continues to evolve its tactics, it remains crucial for organizations to maintain robust cybersecurity measures and stay updated on the latest threat intelligence.
Description last updated: 2024-05-04T20:32:00.119Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Thrip Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more