Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: G0076, ATK78, malicious actors, APT groups, hackers, tracked as, pepper thrips, tobacco thrips, Lotus Panda, Billbug, Spring Dragon, LotusBlossom, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Lotus Blossom

Description

Thrip operates as a clandestine espionage group with a primary focus on satellite communications, telecoms, defense contractors, aerospace, financial services, healthcare, manufacturing, aviation, oil & gas, gaming, retail, mining, media, education, and government organizations. Originating from China, the actors have been linked to multiple aliases including G0030, G0076, ATK78, Lotus Blossom, BRONZE ELGIN, and DRAGONFISH, among others. Their campaigns extend across the United States, Taiwan, India and other Asian countries, often targeting firms that provide critical infrastructure or possess sensitive data. Technically, Thrip demonstrates a hybrid approach: they develop bespoke malware—such as custom infostealers—to harvest credentials and exfiltrate them, while simultaneously abusing legitimate Windows utilities like PowerShell, PsExec, WinSCP, LogMeIn, certutil, and BITSAdmin to maintain stealth and persistence. The group frequently deploys legacy backdoor Trojans including W32/BackDoor.A!tr and W32/Syndicasec.C!tr, enabling long‑term access and data staging. Their use of “living off the land” tactics, coupled with encrypted channels (T1573) and exploit chains (e.g., T1190), reflects an intent to operate undetected across corporate networks. Thrip’s operations exhibit a mix of reconnaissance, credential dumping via Mimikatz, lateral movement through administrative shares, data collection, staging, and exfiltration over FTP or alternative protocols. They occasionally leverage phishing emails and web shells for initial access, then expand privileges using techniques such as Group Policy manipulation (T1484) and Remote Desktop or VNC software to achieve command‑and‑control capabilities.

Goals & Targeting

Targeted Sectors

Telecommunications
Government
Defense
Aerospace
Financial services
Education
Manufacturing
Media
Aviation
Healthcare
Oil gas
Retail
Mining
Gaming

Targeted Countries / Regions

CN
TW
IN
US

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Thrip is a China‑based espionage adversary that targets satellite communications, telecommunications, defense contractors and other high-value sectors in the U.S. and Southeast Asia. The group blends legitimate administrative tools with custom malware—especially PowerShell scripts—to gain footholds, move laterally, exfiltrate data via WinSCP over FTP or other channels, and maintain persistence through backdoor Trojans. Their operations are sophisticated enough to evade detection by leveraging living‑off‑the‑land tactics while still employing well-known hacking tools for credential theft and remote control.

Goals & Targeting

Thrip’s strategic objective is espionage—gathering proprietary and classified information from satellite operators, defense contractors, telecom providers and other sectors deemed critical to national security. By targeting organizations that manage sensitive payloads, communications infrastructure, or financial data, the actors aim to compromise mission‑critical systems or acquire actionable intelligence that could be leveraged for future cyber-operations, influence campaigns or geopolitical advantage.

Enhanced Description

Key Capabilities

  • Custom malware development
  • Living off the land with legitimate tools
  • PowerShell-based command execution and reconnaissance
  • Credential dumping with Mimikatz
  • Lateral movement via PsExec and Windows Admin Shares
  • Remote access using LogMeIn and Remote Desktop
  • Exfiltration through WinSCP over FTP or alternative protocols
  • Use of backdoor Trojans (W32/BackDoor.A!tr, W32/Syndicasec.C!tr)
  • Infostealer malware for credential theft
  • Deployment of legacy exploitation tools and web shells

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration

ATT&CK Techniques

T1001
T1003
T1014
T1021.004
T1041
T1048
T1048.003
T1059
T1059.001
T1059.003
T1087
T1098
T1110
T1119
T1134
T1140
T1190
T1197
T1203
T1219
T1560
T1573
T1583
T1586
T1588
T1595
T1543
T1546
T1555
T1567
T1568
T1484
T1685

Software / Tooling

PowerShell
PsExec
WinSCP
LogMeIn
Mimikatz
Custom malware
Infostealer
W32/BackDoor.A!tr
W32/Syndicasec.C!tr
crimson
DUSTTRAP
certutil
PowerSploit
BITSAdmin
phishing emails
web shell

Campaigns & Victims

Thrip’s campaigns are typically launched as part of a broader intelligence-gathering effort against high-value targets in the satellite communications and defense industries. The group appears to operate with a measured tempo, deploying custom code for persistence, then leveraging well-known living‑off‑the‑land tools to avoid detection. Victims are often large enterprises or contractors with substantial network footprints and critical operations. Notably, Thrip has executed attacks where they disabled satellite functions or accessed secure data from defense-related facilities — showcasing both the breadth of their capabilities and a focus on operational impact.

IOC Patterns

  • PowerShell execution scripts
  • WinSCP FTP exfiltration
  • LogMeIn remote session usage
  • PsExec lateral movement commands
  • Backdoor trojan installation (W32/BackDoor.A!tr, W32/Syndicasec.C!tr)
  • Custom infostealer operations

Recommended Actions

  • Enable and monitor detailed PowerShell logging to detect suspicious scripts.
  • Restrict outbound FTP traffic unless required for legitimate business and alert on anomalous WinSCP usage.
  • Enforce strict access controls on remote administration tools (LogMeIn, RDP, VNC, TeamViewer) and monitor their activity logs.
  • Deploy endpoint detection that flags credential dumping tools such as Mimikatz or evidence of PsExec activity.
  • Implement least privilege for administrative accounts to minimize lateral movement opportunities.
  • Maintain up‑to‑date signature databases for known backdoor Trojans (W32/BackDoor.A!tr, W32/Syndicasec.C!tr).
  • Conduct regular vulnerability assessments focusing on public-facing applications to mitigate exploitation via T1190.
  • Educate users about phishing emails and enforce email filtering to block malicious attachments or links.

Suggested Tags

Thrip
APT
China-based
satellite-communications
telecom
defense-contractor
living-off-the-land
PowerShell
WinSCP
LogMeIn
PsExec
Legitimate-tool-abuse
Credential-dumping
Remote-administration
Backdoor-trojan
Stealth-operations

Confidence Assessment

The confidence in the core facts—such as Thrip’s national origin, sector focus, use of PowerShell and PsExec, and employment of custom infostealers—is high due to multiple corroborating sources. However, gaps remain regarding precise dates of first appearance and comprehensive attribution evidence for all listed aliases. Some technique mappings rely on inferred tactics rather than confirmed exploitation records, suggesting a moderate level of uncertainty around the full breadth of their operational capabilities.

ATT&CK Techniques

Discovery
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Symantec Thrip June 2018 — Security Response Attack Investigation Team. (2018, June 19). Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies. Retrieved July 10, 2018.
  2. apt.etda.or.th — Cited by web research for: LotusBlossom
  3. attack.mitre.org — Cited by web research for: T1059
  4. attack.mitre.org — Cited by web research for: T1134
  5. www.fortinet.com — Cited by web research for: CVE-2019-0708
  6. https://westoahu.hawaii.edu/cyber/uncategorized/chinese-apt-thrip-identified/ — Cited by AI analysis.
  7. https://attack.mitre.org/groups/G0030/ — Cited by AI analysis.

Intel Summary

45

Techniques

55

Tools

0

Campaigns

36

IOCs

0

Observed Data

15

Tactics

Tags

APT
espionage
satellite_communications
telecommunications
defense_contractors
Thrip
China-based
satellite-communications
telecom
defense-contractor
living-off-the-land
PowerShell
WinSCP
LogMeIn
PsExec
Legitimate-tool-abuse
Credential-dumping
Remote-administration
Backdoor-trojan
Stealth-operations

Details

MITRE ID
G0076
Type
Unknown
Primary Motivation
Espionage
Country of Origin
Taiwan (TW)
Confidence
90%
Added
Jul 13, 2026
STIX ID
intrusion-set--d69e568e-9ac8-4c08-b32c-d93b43ba9172
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.