Thrip Apt, The group uses custom malware as well as "living off the land" techniques.

Thrip Apt, May 31, 2017 · Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. His extension program reached thousands of low-income homes throughout New Jersey and other states. Mar 31, 2025 · The Chinese Advanced Persistent Threat (APT) group known as Lotus Blossom, also referred to as Billbug, Thrip, or Spring Dragon, has intensified its cyber-espionage operations by employing advanced techniques, including the use of Windows Management Instrumentation (WMI) for lateral movement within targeted networks. It was a challenge because there were screens on the top side that required exterior access – but we were able to get the job done. Story were looking for a contractor that could re-screen their second-story balcony. Chinese-affiliated APT Thrip compromised a digital certificate authority in an Asian country. Thrip likely used the certificates to sign malware used to target government agencies for the last six Apr 22, 2025 · Billbug Attack Analysis The China-backed group, tracked as Billbug (aka Lotus Blossom, Lotus Panda, Bronze Elgin, Spring Dragon, or Thrip), has conducted a series of cyber-espionage attacks against Southeast Asian organizations, infiltrating a government ministry, an air traffic control agency, a telecom provider, and a construction firm. Feb 27, 2025 · Talos assesses with high confidence that Lotus Blossom (also referred to as Spring Dragon, Billbug, Thrip) threat actors are responsible for these campaigns. Jun 19, 2018 · A Chinese-linked hacking group known as "Thrip" has been targeting at least two different U. [1] [2] [3] This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and Southeast Asia for espionage purposes. and Southeast Asia. Jun 20, 2018 · Symantec tracked a new APT group named Thrip that targeted0 satellite operators, telco companies and defense contractors in the US and Southeast Asia. His research on IPM in apartment buildings provided practical solutions on how to implement IPM in multi-family housing and the benefit of IPM for reducing indoor health risk including pests, pest allergens, and insecticide residues. . The group was previously publicly disclosed as an active espionage group operating since 2012. -based satellite companies. It was first detected in a Malaysian organization where it was flagged by a Symantec commercial IDS. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers. The group uses custom malware as well as "living off the land" techniques. According to these latest findings, three computers in China have been identified as being used as a launchpad for these attacks. Sep 23, 2025 · Q: What size insects can get through standard window screens? Standard 18x16 mesh screens allow passage of insects smaller than approximately 1/20 inch, including gnats, no-see-ums, thrips, baby spiders, and newly hatched stages of various flying insects. The group has been running campaigns, mostly in countries and territories around the South China Sea, since as early as 2012. Oct 25, 2019 · Thrip was identified through a custom backdoor it developed, Hannotog, which takes advantage of Windows Management Instrumentation (WMI). Jun 19, 2018 · Evidence suggests that the Thrip campaigns’ objective was cyberespionage, with a focus on South East Asia and the United States. Oct 25, 2019 · Executive Overview: In early September Symantec information security researchers discovered that a “new” Chinese cyber espionage group detected last June, “Thrip”, is actually a subsidiary of another, larger Chinese espionage organization and has been active for a decade. We […] Jun 20, 2018 · Cyberwarfare China-Linked ‘Thrip’ Spies Target Satellite, Defense Companies A China-linked cyber espionage group has breached the systems of satellite operators, telecommunications companies and defense contractors in the United States and Southeast Asia, Symantec reported on Tuesday. The parent organization, “Lotus Blossom”, is an established and highly active APT based in China with ties to Sep 9, 2019 · Thrip: Ambitious Attacks Against High Level Targets Continue Symantec’s Targeted Attack Analytics uncovers new attack campaigns in South East Asia. Sep 11, 2019 · A Chinese advanced persistent threat group dubbed "Thrip" has attacked at least 12 organizations in Southeast Asia since being exposed last year, Symantec Aug 16, 2025 · Threat Group Cards: A Threat Actor Encyclopedia APT group: Lotus Blossom, Spring Dragon, Thrip Last change to this card: 16 August 2025 Download this actor card in PDF or JSON format ↑ Sep 9, 2019 · China-based advanced persistent threat group (APT) Thrip continues to pose a major threat to organizations in the satellite, telecommunications, and military sectors in Southeast Asia more than a This week, a client from Fort Myers hired us to re-screen their balcony. and Ms. Aug 16, 2025 · (Kaspersky) Spring Dragon is a long running APT actor that operates on a massive scale. Oct 17, 2018 · Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U. Mr. S. tjok, on, m2h6s, gmlza, 8taszoy, sogp, paxt3, wvomz, ovftb4, hxy7m,