Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors AVIVORE

Description

**Targets:** Aerospace and defence industries in the UK and Europe **Toolset/Malware:** PlugX, Mimikatz, WmiExec

TTP Summary

Airbus Attack

Goals & Targeting

Targeted Sectors

Defense
Aerospace & defense

Targeted Countries / Regions

GB
europe

AI Analysis

· 1 week ago

Executive Summary

AVIVORE is a nation-state threat actor targeting defense and aerospace industries primarily in the UK and Europe. Specializing in espionage, AVIVORE employs a toolset including PlugX, Mimikatz, and WmiExec. Their activities have been observed in campaigns like 'Airbus Attack,' highlighting their capability to breach critical sectors for sensitive information.

Goals & Targeting

AVIVORE targets defense and aerospace industries within the UK and Europe for espionage purposes. Their goal is likely to extract sensitive technical data and intellectual property useful for military and strategic advantage. The choice of sectors indicates a focus on enhancing national capabilities through intelligence gathered from these strategically significant areas.

Enhanced Description

AVIVORE is a state-sponsored cyber threat actor known for targeting defense and aerospace industries across the UK and Europe. Their primary motivation is espionage, seeking to gather strategic and technical intelligence from these high-value sectors. AVIVORE's operations are characterized by their use of sophisticated tools such as PlugX, Mimikatz, and WmiExec. PlugX allows remote control and command of infected systems, while Mimikatz is used for credential dumping. WmiExec enables persistence through Windows Management Instrumentation. These techniques were notably observed in the `Airbus Attack` campaign. AVIVORE's targeting strategy suggests a focus on nation-state interests, likely aiming to compromise defense contractors and related entities to acquire advanced technology or national security information.

Key Capabilities

  • PlugX remote access tool
  • Mimikatz credential dumping
  • WmiExec persistence

MITRE ATT&CK Tactics

Credential Access
Persistence

ATT&CK Techniques

T1055
T1078.004

Software / Tooling

PlugX
Mimikatz
WmiExec

Campaigns & Victims

AVIVORE's known campaign patterns include targeting aerospace firms and using techniques like WMI-based persistence and credential dumping. Their operational tempo appears deliberate, focusing on high-value targets within the defense sector. Notable operations include the `Airbus Attack`, demonstrating their ability to compromise major defense contractors.

IOC Patterns

  • Use of PlugX RAT
  • Mimikatz credential extraction activities
  • WMI activity indicative of AVIVORE campaigns

Recommended Actions

  • Implement WMI monitoring and restrictions
  • Enhance OS patching and vulnerability management
  • Monitor for known malicious domains or IPs linked to AVIVORE

Suggested Tags

APT
espionage
defense-sector

Confidence Assessment

Confidence in AVIVORE's details is moderate due to limited公开 information on their TTPs and origins. Gaps include specific campaign history and exact nation-state affiliation.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

3

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
espionage
defense-sector

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.