Avivore
The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that compromise smaller engineering services and consultancies working in their supply chains.
Avivore compromises smaller supply chain firms to infiltrate large enterprises through trusted third-party access.
Avivore is a threat actor that compromises smaller engineering and consultancy firms within supply chains to infiltrate large multinational enterprises. Given the limited data, specific TTPs and tools are not detailed, but the primary objective appears to be gaining initial access through trusted third-party relationships. Defenders must focus on supply chain risk management, strictly auditing third-party access and monitoring lateral movement from partner networks.
The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that compromise smaller engineering services and consultancies working in their supply chains.
Avivore infiltrates large multinational enterprises by compromising smaller engineering services and consultancies within their supply chains.
Based on the provided information, the primary objective of Avivore is to gain initial access by leveraging trusted third-party relationships.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.