Thrip, also tracked as BRONZE THORNWELL and BRONZE ELGIN, is a China-based threat group active since at least 2013. The group is associated primarily with cyber-espionage activity and has shown a sustained interest in defense, satellite, and telecommunications organizations, including entities involved in geospatial imaging and satellite communications operations. Reported targeting has included environments supporting geographic information systems and computers used to monitor and control satellites, indicating an operational focus on strategically sensitive communications and aerospace-related infrastructure. The group has been linked to custom malware including Catchamas and Rikamanu, as well as other associated trojans, and is noted for extensive use of living-off-the-land techniques after initial compromise. Its tradecraft is consistent with post-compromise data theft and long-term access in victim environments. Available reporting supports espionage as the dominant motivation, while the possibility of disruptive intent has been noted but is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.