Chinese Hacking Group Attacks Satellite, Telecom Operators

Photo of Paul Ausick
By Paul Ausick Updated Published
This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
Chinese Hacking Group Attacks Satellite, Telecom Operators

© scyther5 / iStock

A hacking group known as Thrip has launched cyberattacks on two U.S. satellite companies, a private company that sells geospatial imaging technology, and a defense contractor from a location in China. Three Southeast Asian telecom operators were also attacked.

The attacks were publicly reported Tuesday by researchers at Symantec, who discovered the attacks late last year and reported them to the U.S. government earlier this year.

The researchers first spotted Thrip in 2013, but the group went dormant in 2015 following an agreement between Chinese President Xi Jinping and U.S. President Barack Obama on cyberattacks against economic targets. According to CyberScoop, the agreement did not cover conventional espionage targets like defense contractors and federal agencies.

In the new attacks that started late last year when talk of a U.S.-China trade war heated up, Thrip combines readily available tools that are used for legitimate purposes and can be used by malicious actors to insert malware into their targeted systems. Using these tools and adding custom-built attacking software allowed Thrip to steal credentials, move easily through a company’s computer network and insert more remote access backdoors to give themselves wider access to targeted systems.

[nativounit]

Symantec senior threat intelligence analyst Jon DiMaggio told CyberScoop:

We could see based on where they were spending their time and effort that they were really trying to go after this satellite company. They were enumerating directories, manually looking for very specific things like this one software program and the command and control for the satellites … it was much more careful than scanning. They were going after total access, going after the backend databases of these systems as well. Most of the computers at the company didn’t touch the satellites, so they were quite focused.

The researchers also cited their most worrying discovery:

… Thrip had targeted a satellite communications operator. The attack group seemed to be particularly interested in the operational side of the company, looking for and infecting computers running software that monitors and controls satellites. This suggests to us that Thrip’s motives go beyond spying and may also include disruption.

The hacking group’s name comes from a variety of garden pests called thrips (both the single and plural form) that damage plants by sucking out their juices. There are more than 6,000 species of the worthless insects.

[recirclink id=469109]

[wallst_email_signup]

Photo of Paul Ausick
About the Author Paul Ausick →

Paul Ausick has been writing for a673b.bigscoots-temp.com for more than a decade. He has written extensively on investing in the energy, defense, and technology sectors. In a previous life, he wrote technical documentation and managed a marketing communications group in Silicon Valley.

He has a bachelor's degree in English from the University of Chicago and now lives in Montana, where he fishes for trout in the summer and stays inside during the winter.

Our $500K AI Portfolio

See us invest in our favorite AI stock ideas for free

Our Investment Portfolio

Continue Reading

Top Gaining Stocks

CBOE Vol: 1,568,143
PSKY Vol: 12,285,993
STX Vol: 7,378,346
ORCL Vol: 26,317,675
DDOG Vol: 6,247,779

Top Losing Stocks

LKQ
LKQ Vol: 4,367,433
CLX Vol: 13,260,523
SYK Vol: 4,519,455
MHK Vol: 1,859,865
AMGN Vol: 3,818,618