NEW: Group Profiler — instant APT intel lookup. Try it →

Suckfly

G0039 China MITRE ATT&CK →

Overview

Suckfly is a China-based threat group that has been active since at least 2014.

Naming & attribution

Suckfly is tracked under 1 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here. Activity attributed since at least 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
SuckflyDiMaggio, J

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • INC Ransom — 3 shared techniques (11% overlap)
  • FIN6 — 4 shared techniques (10% overlap)
  • Silence — 3 shared techniques (10% overlap)
  • menuPass China — 4 shared techniques (9% overlap)
  • GALLIUM China — 3 shared techniques (9% overlap)
  • BlackByte — 4 shared techniques (8% overlap)

TTPs — 5 techniques across 5 tactics

Execution

Stealth

Defense Impairment

Credential Access

Discovery

Tools & malware (1)

Nidiran

Reporting (2)