Suckfly

G0039

Threat group.View on attack.mitre.org

About this group

Suckfly is a China-based threat group that has been active since at least 2014.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1003
OS Credential Dumping

Suckfly used a signed credential-dumping tool to obtain victim account credentials.

T1046
Network Service Discovery

Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open.

T1059.003
Windows Command Shell

Several tools used by Suckfly have been command-line driven.

T1078
Valid Accounts

Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner.

T1553.002
Code Signing

Suckfly has used stolen certificates to sign its malware.

Software1

Campaigns0

None recorded.

References1

  1. Symantec Suckfly March 2016 Open source
    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.