Skip to content

Hide Navigation Hide TOC

Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d)

Suckfly is a China-based threat group that has been active since at least 2014. (Citation: Symantec Suckfly March 2016)

Cluster A Galaxy A Cluster B Galaxy B Level
Valid Accounts - T1078 (b17a1a56-e99c-403c-8948-561df0cffe81) Attack Pattern Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set 1
Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set APT22 (5abb12e7-5066-4f84-a109-49a037205c76) Threat Actor 1
Nidiran - S0118 (9e9b9415-a7df-406b-b14d-92bfe6809fbe) Malware Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set 1
Network Service Discovery - T1046 (e3a12395-188d-4051-9a16-ea8e14d07b88) Attack Pattern Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set 1
Code Signing - T1553.002 (32901740-b42c-4fdd-bc02-345b5dc57082) Attack Pattern Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set 1
Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set 1
Suckfly - G0039 (5cbe0d3b-6fb1-471f-b591-4b192915116d) Intrusion Set OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) Attack Pattern 1
Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) Attack Pattern Nidiran - S0118 (9e9b9415-a7df-406b-b14d-92bfe6809fbe) Malware 2
Ingress Tool Transfer - T1105 (e6919abc-99f9-4c6c-95a5-14761e7b2add) Attack Pattern Nidiran - S0118 (9e9b9415-a7df-406b-b14d-92bfe6809fbe) Malware 2
Nidiran - S0118 (9e9b9415-a7df-406b-b14d-92bfe6809fbe) Malware Masquerade Task or Service - T1036.004 (7bdca9d5-d500-4d7d-8c52-5fd47baf4c0c) Attack Pattern 2
Subvert Trust Controls - T1553 (b83e166d-13d7-4b52-8677-dff90c548fd7) Attack Pattern Code Signing - T1553.002 (32901740-b42c-4fdd-bc02-345b5dc57082) Attack Pattern 2
Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern 2
Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) Attack Pattern Create or Modify System Process - T1543 (106c0cf6-bf73-4601-9aa8-0945c2715ec5) Attack Pattern 3
Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern Masquerade Task or Service - T1036.004 (7bdca9d5-d500-4d7d-8c52-5fd47baf4c0c) Attack Pattern 3