• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • NEWS:
  • SatNews
  • SatMagazine
  • MilSatMagazine
  • SmallSat News
  • |     EVENTS:
  • SmallSat Symposium
  • Satellite Innovation
  • MilSat Symposium
  • SmallSat Europe

SatNews

Satellite Industry Intelligence Since 1983

Subscribe
  • LATEST
  • SatNews Events
  • Magazines
  • Calendar
  • Subscribe
  • Missions & Constellations
    • Exploration & Science Missions
    • In-Orbit Servicing & Orbital Operations
    • LEO Constellations
    • Mission Autonomy & Onboard Systems
    • Mission Deployments & Manifests
    • Navigation & PNT
    • SmallSat
    • Spacecraft & Payload Technology
    View All in Missions & Constellations →
    Analyst Projects Massive Subscription Growth for Starlink Ahead of Imminent SpaceX IPOAnalyst Projects Massive Subscription Growth for Starlink Ahead of Imminent SpaceX IPO
    KSAT and iQPS Expand Strategic Alliance to Accelerate High-Frequency SAR ConstellationKSAT and iQPS Expand Strategic Alliance to Accelerate High-Frequency SAR Constellation
    Kaman Precision Products Deploys Advanced Magnetic Sensors for Next-Generation Launch PropulsionKaman Precision Products Deploys Advanced Magnetic Sensors for Next-Generation Launch Propulsion
    Beyond Gravity Launches Advanced Propulsion Pointing Mechanism for LEO ConstellationsBeyond Gravity Launches Advanced Propulsion Pointing Mechanism for LEO Constellations
  • Business
    • Contracts & Commercial Deals
    • Earnings & Financial Reporting
    • Events & Conferences
    • Funding & Venture Capital
    • Market Forecasts
    • Mergers & Acquisitions
    • Personnel Moves & Appointments
    View All in Business & Finance →
    Pilot Photonics Secures €1M ESA Contract to Advance Space PhotonicsPilot Photonics Secures €1M ESA Contract to Advance Space Photonics
    Space Stocks in Focus: Zacks Investment Ideas Highlights Gilat, Satellogic, and EchoStarSpace Stocks in Focus: Zacks Investment Ideas Highlights Gilat, Satellogic, and EchoStar
    Lockheed Martin UK Announces Major Workforce Expansion with Up to 2,000 New Space JobsLockheed Martin UK Announces Major Workforce Expansion with Up to 2,000 New Space Jobs
    Voyager Technologies Acquires Astrobotic for $300 MillionVoyager Technologies Acquires Astrobotic for $300 Million
  • Defense
    • Counterspace & ASAT
    • Defense Budgets & Procurement
    • ISR & Reconnaissance
    • MILSATCOM
    • Missile Warning & Defense
    • National Security Programs
    • Space Domain Awareness
    View All in Military & Defense →
    American military space closed around one company in seven daysAmerican military space closed around one company in seven days
    MDA Space Selected by BAE Systems for U.S. Space Force Missile Warning ConstellationMDA Space Selected by BAE Systems for U.S. Space Force Missile Warning Constellation
    ParaZero Secures First DefendAir Order from U.S. Tier-1 Defense CorporationParaZero Secures First DefendAir Order from U.S. Tier-1 Defense Corporation
    Northrop Grumman Partners with Apex for Space-Based Interceptors Targeting 2027 DeliveryNorthrop Grumman Partners with Apex for Space-Based Interceptors Targeting 2027 Delivery
  • Gov
    • Export Controls & Compliance
    • International Space Agreements
    • National Space Policy
    • Space Law & Treaties
    • Space Sustainability & Debris Policy
    • Space Traffic Management / Debris Removal
    View All in Government & Regulation →
    Major opportunities for 2 GHz over EuropeMajor opportunities for 2 GHz over Europe
    “Dual-use” is the funding word. It’s also the label operators want off.“Dual-use” is the funding word. It’s also the label operators want off.
    Sovereignty got an answer on Day 3. Two answers, actually, and a commercial veto.Sovereignty got an answer on Day 3. Two answers, actually, and a commercial veto.
    Dependency killed the old debate. Sovereignty is the new one, and Europe hasn’t agreed what it means.Dependency killed the old debate. Sovereignty is the new one, and Europe hasn’t agreed what it means.
  • Launch
    • Launch Providers
    • Launch Schedule & Calendars
    • Launch Sites & Infrastructure
    • Rocket Technology & Vehicles
    View All in Launch →
    Twelve Scientific Payloads Experience Microgravity Aboard SubOrbital Express-5Twelve Scientific Payloads Experience Microgravity Aboard SubOrbital Express-5
    Amazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V LaunchAmazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V Launch
    If You Thought Space Was Hard Try to Get Your Satellite On a RocketIf You Thought Space Was Hard Try to Get Your Satellite On a Rocket
    Blue Origin Suffers Major Setback as New Glenn Rocket Explodes During Static Fire TestBlue Origin Suffers Major Setback as New Glenn Rocket Explodes During Static Fire Test
  • Software
    • Autonomous Ground Operations
    • Data Processing & AI/ML
    • Digital Twins & Modeling
    • Ground Segment & Teleports
    • Mission Planning & Simulation
    • Space Systems Software Engineering
    • Spectrum & Licensing
    View All in Software Automation & Ground Systems →
    KSAT and Axelspace Expand Strategic Partnership to Accelerate Earth ObservationKSAT and Axelspace Expand Strategic Partnership to Accelerate Earth Observation
    Europe has ships. SmallSat Europe said it doesn’t have ports.Europe has ships. SmallSat Europe said it doesn’t have ports.
    The orbital data center thesis just became an economics question.The orbital data center thesis just became an economics question.
    AI just reached production in European space. The trust problem is what comes next.AI just reached production in European space. The trust problem is what comes next.
  • Services & Apps
    • Climate & Environmental Monitoring
    • Disaster Response & Security Mapping
    • Earth Observation & Imaging
    • Maritime & Aviation Satcom
    • Satellite Communications
    View All in Services & Applications →
    Viasat Secures Lockheed Martin Contract for NOAA’s Next-Generation AircraftViasat Secures Lockheed Martin Contract for NOAA’s Next-Generation Aircraft
    SES Partners with Viva to Launch Multi-Orbit In-Flight ConnectivitySES Partners with Viva to Launch Multi-Orbit In-Flight Connectivity
    Resolve Optics Delivers Radiation-Resistant Lenses for LEO SatellitesResolve Optics Delivers Radiation-Resistant Lenses for LEO Satellites
    SITAEL Unveils €200 Million Growth Strategy and ESA Mission Contract at SmallSat EuropeSITAEL Unveils €200 Million Growth Strategy and ESA Mission Contract at SmallSat Europe

Symantec’s AI Cyber Security Product Prevents a Cyber Attack from Thrip, a Notorious Group

June 20, 2018

This company's artificial intelligence, cyber security product actually saved them from an attack from a notorious group that has caused much distress in organizations and companies that cover industries involved in everything from satellite communications, telecoms, geospatial imaging, and defense organizations in the United States and Southeast Asia. Who is this company, and what is their product?

Symantec Corp.'s (NASDAQ: SYMC) researchers exposed a new attack campaign from a group called Thrip using TAA’s advanced AI technology that was instrumental in the discovery of the attack. TAA alerted Symantec’s Attack Investigations team to activity that on the surface appeared innocuous but set them on the path to uncovering the latest campaign conducted by the Thrip group. Symantec has been monitoring Thrip since 2013, and has discovered new tools and techniques used by the group in this most recent set of attacks.

TAA leverages AI and advanced machine learning to comb through Symantec’s data lake of telemetry in order to spot patterns associated with targeted attacks. This technology essentially automates what previously took thousands of hours of analyst time and is available in Symantec’s Advanced Threat Protection (ATP) product.

From an initial alert triggered by TAA in January 2018, Symantec researchers were able to follow a trail that enabled them to determine that the campaign originated from machines based in mainland China. Using these techniques, TAA detected suspicious behavior despite the group’s use of legitimate operating system features and network administration tools in an attempt to evade detection. TAA also uncovered the use of custom malware in these attacks, as well as identifying the types of organizations targeted. Cyber espionage is the group’s likely motive, but given the group has revealed a strategy of compromising operational systems, it could adopt a more aggressive, disruptive stance should it choose to do so.

“This is likely espionage,” said Greg Clark, Symantec CEO. “The Thrip group has been working since 2013 and their latest campaign uses standard operating system tools, so targeted organizations won’t notice their presence. They operate very quietly, blending in to networks, and are only discovered using artificial intelligence that can identify and flag their movements. Alarmingly, the group seems keenly interested in telecom, satellite operators, and defense companies. We stand ready to work with appropriate authorities to address this serious threat.”

Symantec has sharpened its efforts on network-resident malware, as the many vulnerabilities that are widely known in IOT devices present a new attack surface of extreme interest.

Thrip’s attack on telecoms and satellite operators exposes the possibility that the attackers could intercept or even alter communications traffic from enterprises and consumers. This has added to growing privacy concerns that have been very visible lately with the deployment of the new GDPR regulations as well as the VPNFilter attacks on Internet routers. Symantec has responded by opening a new privacy center and data protection lab in order to provide consumers with more control over their data, and organizations with tools to help them responsibly manage the data they handle. Symantec also offers a wide variety of privacy solutions, such as Symantec VIP and Norton WiFi Privacy.

Symantec has been protecting customers from Thrip-related activity since 2013. The following protections are in place to protect customers against Thrip:

  • File-based protection
  • Trojan.Rikamanu
  • Infostealer.Catchamas
  • Hacktool.Mimikatz
  • Trojan.Mycicil
  • Backdoor.Spedear
  • Trojan.Syndicasec

Customers of Symantec’s DeepSight Intelligence Managed Adversary and Threat Intelligence (MATI) service have received multiple reports on “ATG14” (also known as Thrip), which detail methods of detecting and thwarting activities of this adversary.

 

Filed Under: National Security Programs

Primary Sidebar

Coverage

  • Missions & Constellations
  • Business & Finance
  • Military & Defense
  • Launch
  • Software Automation & Ground Systems
  • Government & Regulation
  • Services & Applications

Most Read Stories

  • AST SpaceMobile Pivots to SpaceX for Mid-June Launch of Three BlueBird Satellites
  • SmallSat Europe Speaker Focus: Frank M. Salzgeber, Nadir Space Venture
  • SpaceX Debuts Starship V3: Redefining Heavy-Lift Launch Capability
  • SpaceX Accelerates Transition from Falcon 9 to Next-Generation Starship Fleet
  • SpaceX Is Worth $1.75 Trillion. Only 7% of That Is Real.

Secondary Sidebar

Footer

 

Satnews is a leading provider of satellite news, events, publications, research and other satellite industry information in both commercial and military enterprises worldwide.

Stories By Category

  • Business & Finance
  • Government & Regulation
  • Launch
  • Military & Defense
  • Missions & Constellations
  • Services & Applications
  • Software Automation & Ground Systems
  • Spectrum & Licensing
  • Startups & NewSpace Business

About Us

  • Leadership & Editorial Team
  • SatNews History
  • Free Satnews Subscription
  • SatNews Events
  • Magazines

Navigation

  • Latest Stories
  • Magazines
  • Events
  • Contact
  • Cookie & Privacy Policy for Satnews

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
x
Sign up Now (For Free)
Access daily or weekly satellite news updates covering all aspects of the commercial and military satellite industry.
Invalid email address
Notify Me Regarding ( At least one ):
We value your privacy and will not sell or share your email or other information with any other company. You may also unsubscribe at anytime.

Click Here to see our full privacy policy.
Thanks for subscribing!