According to a security firm, there are many groups of hackers that are very dangerous and we are ignoring them. Often, when we hear about major attacks on multinationals in Europe and America, our minds go to well-known hackers, such as China's APT10 group. However, this is not always the case. Researchers from the company Context have identified an unknown group, which they have named Avivore.
According to researchers, this group is “smart” enough to cover its tracks effectively. The company believes that the group has been carrying out attacks since 2015.However, most of the attacks were detected in the last year.
Researchers now believe that Avivore was behind the recent attacks on Airbus .The attacks were initially linked to the APT10 group and the Chinese State Security Group (JSSD)
The hacking team used partners of Airbus, such as the Rolls‑Royce company and Expleo to affect the airline company.
This reflects the strategy used by Avivore. Hackers use the “island hopping” technique. According to this technique, hackers target a large company indirectly, through its weaker and less protected partners. However, they choose key partners and not companies that could be easily replaced.
One of Context's researchers said: "The companies they target are the only ones who could supply a particular product, so they can't simply be replaced with someone else."

This technique significantly hinders the mitigation of attacks.
Avivore hackers posed as legitimate users to infiltrate supplier networks . They primarily used VPNs and other tools for remote access. This allowed the hackers to bypass the systems of the larger target company while covering their tracks. security
Researchers believe that the group is targeting the intellectual property of its victims. Its goal is not only airlines, but also defense equipment suppliers, automobile manufacturers, energy sector industries, and many others.
The attacks on these entities have led many researchers to link them to APT10 and JSSD. However, AVIVORE uses different tools and tactics.
“There is certainly similarity in the types of industries and technologies they target and it would be logical to assume that these groups have the same motives”, said the Context researcher “but we cannot say that with certainty”.
Whoever is behind the attacks, the only thing certain is that companies need to take more security measures and also take care of the safety of their key suppliers and partners.
