NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the SilverTerrier threat group

SilverTerrier

Overview

SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.

Naming & attribution

It uses 4 documented ATT&CK techniques — more than 9% of the 174 groups tracked here. Activity attributed since 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
SilverTerrierUnit42

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Kimsuky North Korea — 4 shared techniques (3% overlap)

Malware families with tracked indicators

4 families attributed to SilverTerrier, with 1,287 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.

  • AgentTesla 662 indicators
  • NanoCore 545 indicators
  • DarkComet 74 indicators
  • NetWire 6 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 4 techniques across 2 tactics

Command and Control

Impact

Tools & malware (5)

NanoCore · Agent Tesla · NETWIRE · DarkComet · Lokibot

Reporting (2)