Suckfly
Overview
Suckfly is a China-based threat group that has been active since at least 2014.
Naming & attribution
Suckfly is tracked under 1 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here. Activity attributed since at least 2014.
| Name | First reported by |
|---|---|
| Suckfly | DiMaggio, J |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
TTPs — 5 techniques across 5 tactics
Execution
-
T1059.003Windows Command Shell
Stealth
-
T1078Valid Accounts
Defense Impairment
-
T1553.002Code Signing
Credential Access
-
T1003OS Credential Dumping
Discovery
Tools & malware (1)
Nidiran
Reporting (2)
- Indian organizations targeted in Suckfly attacks — DiMaggio, J
- Suckfly: Revealing the secret life of your code signing certificates — DiMaggio, J