• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • NEWS:
  • SatNews
  • SatMagazine
  • MilSatMagazine
  • SmallSat News
  • |     EVENTS:
  • SmallSat Symposium
  • Satellite Innovation
  • MilSat Symposium
  • SmallSat Europe

SatNews

Satellite Industry Intelligence Since 1983

Subscribe
  • LATEST
  • SatNews Events
  • Magazines
  • Calendar
  • Subscribe
  • Missions & Constellations
    • Exploration & Science Missions
    • In-Orbit Servicing & Orbital Operations
    • LEO Constellations
    • Mission Autonomy & Onboard Systems
    • Mission Deployments & Manifests
    • Navigation & PNT
    • SmallSat
    • Spacecraft & Payload Technology
    View All in Missions & Constellations →
    The Silent Overhaul: How Software-Defined Routing and Cloud Ingestion Flattened the Aerospace Hardware StackThe Silent Overhaul: How Software-Defined Routing and Cloud Ingestion Flattened the Aerospace Hardware Stack
    Hybrid Earth Intelligence: NASA Expands Commercial Satellite Data Integration in $476M Cloud-Driven PushHybrid Earth Intelligence: NASA Expands Commercial Satellite Data Integration in $476M Cloud-Driven Push
    Hybrid Edge Mobility: Contrivian Launches “Horizon Plus” to Deliver Intelligent Multi-Orbit Field CommunicationsHybrid Edge Mobility: Contrivian Launches “Horizon Plus” to Deliver Intelligent Multi-Orbit Field Communications
    Space Tech vs. Biothreat: GMV Deploys Earth Observation and AI Core to Fight Invasive Pacific Seaweed in PortugalSpace Tech vs. Biothreat: GMV Deploys Earth Observation and AI Core to Fight Invasive Pacific Seaweed in Portugal
  • Business
    • Contracts & Commercial Deals
    • Earnings & Financial Reporting
    • Events & Conferences
    • Funding & Venture Capital
    • Market Forecasts
    • Mergers & Acquisitions
    • Personnel Moves & Appointments
    View All in Business & Finance →
    The Spatial Photonics Crunch: Inside the Invisible Supply Chain Threatening Orbital Laser NetworksThe Spatial Photonics Crunch: Inside the Invisible Supply Chain Threatening Orbital Laser Networks
    Sovereign Space Expansion: Spain’s FOSSA Systems Secures €9.25M to Scale Defense Constellation and SIGINT InfrastructureSovereign Space Expansion: Spain’s FOSSA Systems Secures €9.25M to Scale Defense Constellation and SIGINT Infrastructure
    Next-Gen Spatial Intelligence: BAE Systems Secures Agreement to Build High-Resolution Vantage Satellite Buses for VantorNext-Gen Spatial Intelligence: BAE Systems Secures Agreement to Build High-Resolution Vantage Satellite Buses for Vantor
    New Lobbying Force: Top NGSO Operators Unveil “SpaceConnect Association” in WashingtonNew Lobbying Force: Top NGSO Operators Unveil “SpaceConnect Association” in Washington
  • Defense
    • Counterspace & ASAT
    • Defense Budgets & Procurement
    • ISR & Reconnaissance
    • MILSATCOM
    • Missile Warning & Defense
    • National Security Programs
    • Space Domain Awareness
    View All in Military & Defense →
    Digital Twins for Space Command: Sedaro Tapped by Space Force to Build Federated Engineering PlatformDigital Twins for Space Command: Sedaro Tapped by Space Force to Build Federated Engineering Platform
    The Strategic Redistribution of Iranian Aerospace CapabilityThe Strategic Redistribution of Iranian Aerospace Capability
    Navigating Contested Battlespaces: Military GPS Receiver Market Approaches $3 Billion Amid Electronic Warfare SurgeNavigating Contested Battlespaces: Military GPS Receiver Market Approaches $3 Billion Amid Electronic Warfare Surge
    Preparing for Day One: DARPA Solicits Tech to Rebuild Destroyed Satellite Fleets Within HoursPreparing for Day One: DARPA Solicits Tech to Rebuild Destroyed Satellite Fleets Within Hours
  • Gov
    • Export Controls & Compliance
    • International Space Agreements
    • National Space Policy
    • Space Law & Treaties
    • Space Sustainability & Debris Policy
    • Space Traffic Management / Debris Removal
    View All in Government & Regulation →
    $3.57 Billion Milestone: FCC Advanced Wireless Services (AWS-3) Spectrum Auction Concludes$3.57 Billion Milestone: FCC Advanced Wireless Services (AWS-3) Spectrum Auction Concludes
    Who Has Authority to Intervene in a Space-Based Emergency?Who Has Authority to Intervene in a Space-Based Emergency?
    Staying in Their Lanes: SpaceX and Globalstar Join Forces to Defend Spectrum ExclusivityStaying in Their Lanes: SpaceX and Globalstar Join Forces to Defend Spectrum Exclusivity
    Orbital Paperwork War: China’s Spectrum Squatting Reserves 244,000 Satellite Slots to Combat SpaceX’s LEO MonopolyOrbital Paperwork War: China’s Spectrum Squatting Reserves 244,000 Satellite Slots to Combat SpaceX’s LEO Monopoly
  • Launch
    • Launch Providers
    • Launch Schedule & Calendars
    • Launch Sites & Infrastructure
    • Rocket Technology & Vehicles
    View All in Launch →
    Arianespace fights back – possibly!Arianespace fights back – possibly!
    Direct-to-Device Momentum: AST SpaceMobile Successfully Launches Giant Next-Gen BlueBird Satellites Atop SpaceX Falcon 9Direct-to-Device Momentum: AST SpaceMobile Successfully Launches Giant Next-Gen BlueBird Satellites Atop SpaceX Falcon 9
    SpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry TestsSpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry Tests
    Breaking the TRL Bottleneck: Space Phoenix Systems Debuts Cost-Effective Space Test-and-Return ServiceBreaking the TRL Bottleneck: Space Phoenix Systems Debuts Cost-Effective Space Test-and-Return Service
  • Software
    • Autonomous Ground Operations
    • Data Processing & AI/ML
    • Digital Twins & Modeling
    • Ground Segment & Teleports
    • Mission Planning & Simulation
    • Space Systems Software Engineering
    • Spectrum & Licensing
    View All in Software Automation & Ground Systems →
    Powering the Automated Floor: Intralogistics Operators Must Unify AGV Charging InfrastructurePowering the Automated Floor: Intralogistics Operators Must Unify AGV Charging Infrastructure
    Poland Sovereignty: GMV to Develop Core Ground Control Platform for CAMILA ConstellationPoland Sovereignty: GMV to Develop Core Ground Control Platform for CAMILA Constellation
    Software Over the Air: FatPipe Launches Acceleration Tool to Unclog Starlink and Amazon LEO LinksSoftware Over the Air: FatPipe Launches Acceleration Tool to Unclog Starlink and Amazon LEO Links
    Three LEO Operators Bet 2026 on a Supply Chain Built for 2027Three LEO Operators Bet 2026 on a Supply Chain Built for 2027
  • Services & Apps
    • Climate & Environmental Monitoring
    • Disaster Response & Security Mapping
    • Earth Observation & Imaging
    • Maritime & Aviation Satcom
    • Satellite Communications
    View All in Services & Applications →
    National SAR Defense: Norway Selects ICEYE for Nationwide Space-Based Flood and Hazard Monitoring SystemNational SAR Defense: Norway Selects ICEYE for Nationwide Space-Based Flood and Hazard Monitoring System
    Sovereign Milestone: OQ Technology Achieves Europe’s First Drone Video Transmission via 3GPP NTN LEO SatelliteSovereign Milestone: OQ Technology Achieves Europe’s First Drone Video Transmission via 3GPP NTN LEO Satellite
    Ghost Viewers trigger secondary ripple effect on Satellite Communications (SatCom)Ghost Viewers trigger secondary ripple effect on Satellite Communications (SatCom)
    Fleet-Wide Hybrid Networks: Marlink Integrates Starlink Across 80+ Oldendorff Carriers VesselsFleet-Wide Hybrid Networks: Marlink Integrates Starlink Across 80+ Oldendorff Carriers Vessels

Symantec’s AI Cyber Security Product Prevents a Cyber Attack from Thrip, a Notorious Group

June 20, 2018

This company's artificial intelligence, cyber security product actually saved them from an attack from a notorious group that has caused much distress in organizations and companies that cover industries involved in everything from satellite communications, telecoms, geospatial imaging, and defense organizations in the United States and Southeast Asia. Who is this company, and what is their product?

Symantec Corp.'s (NASDAQ: SYMC) researchers exposed a new attack campaign from a group called Thrip using TAA’s advanced AI technology that was instrumental in the discovery of the attack. TAA alerted Symantec’s Attack Investigations team to activity that on the surface appeared innocuous but set them on the path to uncovering the latest campaign conducted by the Thrip group. Symantec has been monitoring Thrip since 2013, and has discovered new tools and techniques used by the group in this most recent set of attacks.

TAA leverages AI and advanced machine learning to comb through Symantec’s data lake of telemetry in order to spot patterns associated with targeted attacks. This technology essentially automates what previously took thousands of hours of analyst time and is available in Symantec’s Advanced Threat Protection (ATP) product.

From an initial alert triggered by TAA in January 2018, Symantec researchers were able to follow a trail that enabled them to determine that the campaign originated from machines based in mainland China. Using these techniques, TAA detected suspicious behavior despite the group’s use of legitimate operating system features and network administration tools in an attempt to evade detection. TAA also uncovered the use of custom malware in these attacks, as well as identifying the types of organizations targeted. Cyber espionage is the group’s likely motive, but given the group has revealed a strategy of compromising operational systems, it could adopt a more aggressive, disruptive stance should it choose to do so.

“This is likely espionage,” said Greg Clark, Symantec CEO. “The Thrip group has been working since 2013 and their latest campaign uses standard operating system tools, so targeted organizations won’t notice their presence. They operate very quietly, blending in to networks, and are only discovered using artificial intelligence that can identify and flag their movements. Alarmingly, the group seems keenly interested in telecom, satellite operators, and defense companies. We stand ready to work with appropriate authorities to address this serious threat.”

Symantec has sharpened its efforts on network-resident malware, as the many vulnerabilities that are widely known in IOT devices present a new attack surface of extreme interest.

Thrip’s attack on telecoms and satellite operators exposes the possibility that the attackers could intercept or even alter communications traffic from enterprises and consumers. This has added to growing privacy concerns that have been very visible lately with the deployment of the new GDPR regulations as well as the VPNFilter attacks on Internet routers. Symantec has responded by opening a new privacy center and data protection lab in order to provide consumers with more control over their data, and organizations with tools to help them responsibly manage the data they handle. Symantec also offers a wide variety of privacy solutions, such as Symantec VIP and Norton WiFi Privacy.

Symantec has been protecting customers from Thrip-related activity since 2013. The following protections are in place to protect customers against Thrip:

  • File-based protection
  • Trojan.Rikamanu
  • Infostealer.Catchamas
  • Hacktool.Mimikatz
  • Trojan.Mycicil
  • Backdoor.Spedear
  • Trojan.Syndicasec

Customers of Symantec’s DeepSight Intelligence Managed Adversary and Threat Intelligence (MATI) service have received multiple reports on “ATG14” (also known as Thrip), which detail methods of detecting and thwarting activities of this adversary.

 

Filed Under: National Security Programs

Primary Sidebar

Coverage

  • Missions & Constellations
  • Business & Finance
  • Military & Defense
  • Launch
  • Software Automation & Ground Systems
  • Government & Regulation
  • Services & Applications

Most Read Stories

  • SpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry Tests
  • American military space closed around one company in seven days
  • Analyst Projects Massive Subscription Growth for Starlink Ahead of Imminent SpaceX IPO
  • Major opportunities for 2 GHz over Europe
  • Amazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V Launch

Secondary Sidebar

Footer

 

Satnews is a leading provider of satellite news, events, publications, research and other satellite industry information in both commercial and military enterprises worldwide.

Stories By Category

  • Business & Finance
  • Government & Regulation
  • Launch
  • Military & Defense
  • Missions & Constellations
  • Services & Applications
  • Software Automation & Ground Systems
  • Spectrum & Licensing
  • Startups & NewSpace Business

About Us

  • Leadership & Editorial Team
  • SatNews History
  • Free Satnews Subscription
  • SatNews Events
  • Magazines

Navigation

  • Latest Stories
  • Magazines
  • Events
  • Contact
  • Cookie & Privacy Policy for Satnews

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
x
Sign up Now (For Free)
Access daily or weekly satellite news updates covering all aspects of the commercial and military satellite industry.
Invalid email address
Notify Me Regarding ( At least one ):
We value your privacy and will not sell or share your email or other information with any other company. You may also unsubscribe at anytime.

Click Here to see our full privacy policy.
Thanks for subscribing!