← Back to all threat actors

Thrip

Tracked as G0076

Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as "living off the land" techniques.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
RelationshipOverlaps relationship with Lotus Blossom

MITRE lists Thrip as an associated name for Lotus Blossom while retaining Thrip as a separate group record.

Medium
Cataloged
IdentityTracking identifier: G0076

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

ThripCanonical Name
G0076Tracking Id

Shared-name reviews

Every exact-name collision is reviewed. Same-actor decisions select a preferred profile while distinct and unresolved clusters remain separate.

Identity remains unresolved medium

MITRE lists Thrip as an associated name for Lotus Blossom while retaining Thrip as a separate group record. The catalog preserves both records and does not infer exact equivalence.

Loading CVEs, techniques, indicators, malware, victims, and activity...