Thrip is a cyber-espionage threat actor assessed to have operated since at least 2013 and linked at high confidence to infrastructure in mainland China. The group is known for intrusions against telecommunications providers, satellite communications operators, defense companies, and organizations in the geospatial domain, including environments supporting GIS and satellite-related operations. Reported victim geography includes the United States and Southeast Asia. Thrip is characterized by quiet, long-duration operations that rely heavily on standard operating system tools to blend into victim environments and reduce detection opportunities. Observed tradecraft includes initial access followed by stealthy post-compromise activity, lateral movement across enterprise networks, persistence within compromised environments, and data exfiltration in support of intelligence collection. In at least one reported intrusion, the actor moved laterally inside a satellite communications operator to reach satellite monitoring and control systems, demonstrating both operational sophistication and potential access to disruptive effects beyond espionage. The actor’s targeting and behavior indicate a primary focus on strategic intelligence collection involving telecommunications, satellite infrastructure, defense-related entities, and geospatial technologies. While some reporting assessed that access to satellite control environments could have enabled disabling satellites, the strongest corroborated assessment is that Thrip is an espionage-oriented actor with advanced post-exploitation and lateral movement capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.