Thrip
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and Southeast Asia for espionage purposes.
An espionage group targeting US defense and telecom sectors, known for using PowerShell and Mimikatz.
Thrip (ATK78) is an espionage-focused threat actor targeting the US satellite communications, telecommunications, geospatial-imaging, and defense private sector. The actor leverages PowerShell for execution, uses Mimikatz and PsExec for credential theft and lateral movement, and establishes C2 via Remote Desktop Software, deploying Catchamas malware for data exfiltration over unencrypted non-C2 protocols. Defenders should prioritize enabling PowerShell logging, restricting and monitoring PsExec usage, and enforcing network segmentation to detect anomalous outbound data flows.
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and Southeast Asia for espionage purposes.
Monitor network traffic and system logs for obtaining or preparing Tool.
Monitor PowerShell execution events and implement content analysis to detect suspicious scripts.
Implement log and network traffic analysis to detect suspicious Remote Desktop Software usage.
Implement network traffic monitoring to detect exfiltration attempts over unencrypted non-C2 protocols.
It uses the Catchamas malware over unencrypted non-C2 protocols for data exfiltration.
Defenders should enable PowerShell logging to capture and monitor execution.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.