NEW: Group Profiler — instant APT intel lookup. Try it →

SilverTerrier

Overview

SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.

Naming & attribution

SilverTerrier is tracked under 1 names across the industry. It uses 4 documented ATT&CK techniques — more than 9% of the 174 groups tracked here. Activity attributed since 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
SilverTerrierUnit42

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Kimsuky North Korea — 4 shared techniques (3% overlap)

Malware families with current indicators

5 families attributed to SilverTerrier, carrying 1,065 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • DarkComet 303 indicators
  • NanoCore 256 indicators
  • AgentTesla 254 indicators
  • NetWire 251 indicators
  • Lokibot 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 4 techniques across 2 tactics

Command and Control

Impact

Tools & malware (5)

NanoCore · Agent Tesla · NETWIRE · DarkComet · Lokibot

Reporting (2)