Thrip espionage campaign against a satellite communications operator, telecoms and defence targets (2018)
What happened
In January 2018 Symantec's Targeted Attack Analytics flagged malicious activity inside a satellite communications operator, and the investigation that followed found the same actor in a geospatial imaging and mapping organisation, three telecoms operators in South East Asia and a defence contractor. Symantec named the group Thrip and stated that the attacks were launched from three computers in China. What distinguishes the satellite victim from ordinary corporate espionage is where the actor went: Symantec reports that it sought out and infected the computers running the software that monitors and controls satellites, which the company read as an interest that went beyond espionage into possible disruption. The tradecraft was predominantly living off the land, PsExec, PowerShell, Mimikatz, WinSCP and the commercial remote-access product LogMeIn, supplemented by the custom Infostealer.Catchamas. A follow-up investigation published in September 2019 merged Thrip with the older Billbug (Lotus Blossom) group, counted at least twelve victim organisations across six countries and territories, and recorded activity at a satellite communications operator continuing into July 2019, with the Hannotog backdoor deployed as early as January 2017.
This is enterprise-network espionage that reached mission-adjacent ground systems, and the record is mapped on that basis. The one claim that gives it space-segment relevance, that the actor targeted the computers running satellite monitoring and control software, comes from the operator's incident responder rather than from the operator, and Symantec does not say the actor commanded anything. SPARTA's bibliography cites this campaign at eleven techniques; four survive review here, and the seven rejections are recorded in the markdown narrative because most of them are spacecraft-scoped techniques cited as domain context rather than as evidence.
Attack vector
Not stated by the source. Symantec describes the post-compromise tradecraft (living off the land with PsExec, PowerShell, Mimikatz, WinSCP and LogMeIn, plus Infostealer.Catchamas) but does not name the initial access vector.
Operational impact
None reported. Symantec describes targeting of the computers that monitor and control satellites and reads it as interest in disruption, but reports no disruption, no commanding and no effect on any spacecraft.
Data compromised
Not itemised. An information-stealing trojan and a file-transfer client were present on compromised systems; no source states what left.
Affected segments
ground
Disclosed
2018-06-19
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
Symantec frames the campaign as living off the land: the operator's own administrative tools (PsExec, PowerShell) and a commercial remote-access product the organisation already ran (LogMeIn) carried the activity, so it presented as authorised administration. DE-0004's subject is presenting as an authorised origin so that activity is processed without scrutiny. Derived because Symantec describes the tooling and the evasion benefit without stating that any specific identity or origin was impersonated.
Symantec documents the custom Infostealer.Catchamas deployed alongside living-off-the-land tooling on hosts inside the compromised satellite communications operator, and the 2019 follow-up adds the Hannotog and Sagerunex backdoors. Adversary-introduced executable logic ran on victim systems, which is EX-0010's behaviour. Recovered per decision 67: the edge was previously rejected only because SPARTA writes EX-0010 on the vehicle and this code ran on enterprise Windows hosts.
Symantec places an information-stealing trojan (Infostealer.Catchamas) and a file-transfer client (WinSCP) on systems inside the compromised operator, which is the toolset EXF-0007 describes being used to siphon data from a trusted position on the ground. The edge is derived rather than direct because Symantec does not state that data left, or what data.
Symantec states that inside the satellite communications operator the actor sought out and infected computers running software that monitors and controls satellites. IA-0007's subject is compromise of exactly that infrastructure, mission control software and operator workstations, and the source describes the behaviour rather than leaving it to be inferred.
The 2019 follow-up records activity at a satellite communications operator continuing into July 2019 and the Hannotog backdoor deployed from as early as January 2017, which is long-lived residence in mission ground infrastructure rather than a single intrusion. Confidence is moderate rather than high because the 2019 report does not state that the satellite-operator victim it discusses is the same one from the 2018 report.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Symantec says the targeting suggests interest in disruption. No disruption occurred. Motive is not impact.
IMP-0006 is theft of the data a spacecraft gathers, processes and sends. No source states that mission data was taken.
RD-0002 is resource development: compromising infrastructure in order to use it as attack infrastructure. Symantec reports no such reuse of the victims' systems.
The delivery pathways this technique enumerates are TT&C injection, payload downlink manipulation, crosslink abuse and supply-chain update paths. None is described.
Pre-positioning packages in provider portals, scheduler queues or ground station file drops, formatted to mission protocols. Not what happened.
Symantec describes access to control computers, not collection of frequency plans, modulation, framing or pass geometry. Nothing in the source names the technique's object.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Thrip: Espionage Group Hits Satellite, Telecoms, and Defense CompaniesVendor threat intelligence
Tier 2: Named vendor threat-intelligence publication by the team that detected the campaign, with the victim sectors, the tooling and the attribution stated in the vendor's own voice. Not independently corroborated by a government report.
Tier 2: Same vendor, follow-up investigation. Supplies the persistence evidence (Hannotog deployed since January 2017, satellite-operator activity through July 2019) that the 2018 post does not.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.