Uptime Hamster: 10d 10h 55mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Avivore

Avivore

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: Airbus Attack, PlugX, Mimikatz, WmiExec, incluidos la industria aeronáutica, defensa en el Reino Unido, Europa, técnicas de persistencia
Ver en IntelTracker → APTTrail →
Avivore is a threat actor first publicly identified in October 2019, though activity was observed for over a year prior to this disclosure. The group is assessed with moderate confidence to be a nation-state level adversary originating from China, indicated by operations within the UTC+8 timezone and the use of PlugX malware, which has strong ties to Chinese state-sponsored activities. Their primary motivation is cyber espionage, focusing on long-term infiltration and intelligence gathering. Avivore distinguishes itself through a 'island hopping' strategy, compromising smaller engineering and consultancy firms within the supply chain to gain access to larger, more fortified primary targets in the aerospace and defense sectors, effectively bypassing direct perimeter defenses by leveraging trusted third-party access. The group's tactics, techniques, and procedures have been noted to differ from other Chinese-linked groups like APT41 and Turla, suggesting a distinct operational entity.

Aliases del actor

Airbus AttackPlugXMimikatzWmiExecincluidos la industria aeronáuticadefensa en el Reino UnidoEuropatécnicas de persistencia

Actores similares

plugxactor · 1mimikatzactor · 1FastAttackerapt · 0Gangnam Industrial Styleapt · 0
Motivacion