ATT&CKReferencesSymantec Thrip June 2018

Symantec Thrip June 2018

Security Response Attack Investigation Team. (2018, June 19). Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies. Retrieved July 10, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupThrip

Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP.

T1059.001
PowerShell
GroupThrip

Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance.

T1219.002
Remote Desktop Software
GroupThrip

Thrip used a cloud-based remote access software called LogMeIn for their attacks.

T1588.002
Tool
GroupThrip

Thrip has obtained and used tools such as Mimikatz and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.