SilverTerrier
Overview
SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.
Naming & attribution
It uses 4 documented ATT&CK techniques — more than 9% of the 174 groups tracked here. Activity attributed since 2014.
| Name | First reported by |
|---|---|
| SilverTerrier | Unit42 |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Kimsuky North Korea — 4 shared techniques (3% overlap)
Malware families with tracked indicators
4 families attributed to SilverTerrier, with 1,287 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.
- AgentTesla 662 indicators
- NanoCore 545 indicators
- DarkComet 74 indicators
- NetWire 6 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 5 attributed custom malware families
TTPs — 4 techniques across 2 tactics
Command and Control
-
T1071.001Web Protocols -
T1071.002File Transfer Protocols -
T1071.003Mail Protocols
Impact
-
T1657Financial Theft
Tools & malware (5)
NanoCore · Agent Tesla · NETWIRE · DarkComet · Lokibot
Reporting (2)
- SILVERTERRIER: The Next Evolution in Nigerian Cybercrime — Renals, P., Conant, S
- SILVERTERRIER: THE RISE OF NIGERIAN BUSINESS EMAIL COMPROMISE — Unit42