Also known as: G0076, ATK78, malicious actors, APT groups, hackers, tracked as, pepper thrips, tobacco thrips, Lotus Panda, Billbug, Spring Dragon, LotusBlossom, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Lotus Blossom
Thrip operates as a clandestine espionage group with a primary focus on satellite communications, telecoms, defense contractors, aerospace, financial services, healthcare, manufacturing, aviation, oil & gas, gaming, retail, mining, media, education, and government organizations. Originating from China, the actors have been linked to multiple aliases including G0030, G0076, ATK78, Lotus Blossom, BRONZE ELGIN, and DRAGONFISH, among others. Their campaigns extend across the United States, Taiwan, India and other Asian countries, often targeting firms that provide critical infrastructure or possess sensitive data. Technically, Thrip demonstrates a hybrid approach: they develop bespoke malware—such as custom infostealers—to harvest credentials and exfiltrate them, while simultaneously abusing legitimate Windows utilities like PowerShell, PsExec, WinSCP, LogMeIn, certutil, and BITSAdmin to maintain stealth and persistence. The group frequently deploys legacy backdoor Trojans including W32/BackDoor.A!tr and W32/Syndicasec.C!tr, enabling long‑term access and data staging. Their use of “living off the land” tactics, coupled with encrypted channels (T1573) and exploit chains (e.g., T1190), reflects an intent to operate undetected across corporate networks. Thrip’s operations exhibit a mix of reconnaissance, credential dumping via Mimikatz, lateral movement through administrative shares, data collection, staging, and exfiltration over FTP or alternative protocols. They occasionally leverage phishing emails and web shells for initial access, then expand privileges using techniques such as Group Policy manipulation (T1484) and Remote Desktop or VNC software to achieve command‑and‑control capabilities.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Thrip is a China‑based espionage adversary that targets satellite communications, telecommunications, defense contractors and other high-value sectors in the U.S. and Southeast Asia. The group blends legitimate administrative tools with custom malware—especially PowerShell scripts—to gain footholds, move laterally, exfiltrate data via WinSCP over FTP or other channels, and maintain persistence through backdoor Trojans. Their operations are sophisticated enough to evade detection by leveraging living‑off‑the‑land tactics while still employing well-known hacking tools for credential theft and remote control.
Goals & Targeting
Thrip’s strategic objective is espionage—gathering proprietary and classified information from satellite operators, defense contractors, telecom providers and other sectors deemed critical to national security. By targeting organizations that manage sensitive payloads, communications infrastructure, or financial data, the actors aim to compromise mission‑critical systems or acquire actionable intelligence that could be leveraged for future cyber-operations, influence campaigns or geopolitical advantage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Thrip’s campaigns are typically launched as part of a broader intelligence-gathering effort against high-value targets in the satellite communications and defense industries. The group appears to operate with a measured tempo, deploying custom code for persistence, then leveraging well-known living‑off‑the‑land tools to avoid detection. Victims are often large enterprises or contractors with substantial network footprints and critical operations. Notably, Thrip has executed attacks where they disabled satellite functions or accessed secure data from defense-related facilities — showcasing both the breadth of their capabilities and a focus on operational impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core facts—such as Thrip’s national origin, sector focus, use of PowerShell and PsExec, and employment of custom infostealers—is high due to multiple corroborating sources. However, gaps remain regarding precise dates of first appearance and comprehensive attribution evidence for all listed aliases. Some technique mappings rely on inferred tactics rather than confirmed exploitation records, suggesting a moderate level of uncertainty around the full breadth of their operational capabilities.
No campaigns linked yet.
No observed data linked yet.
45
Techniques
55
Tools
0
Campaigns
36
IOCs
0
Observed Data
15
Tactics