Suckfly

MITRE ATT&CK: G0039 View on attack.mitre.org

Aliases: Suckfly, BRONZE OLIVE, Group 46

First seen
2014-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:32:11

Targeted industries: financial-services government-and-public-sector manufacturing technology-and-telecommunications

Targeted regions: country_code:in country_code:kr country_code:hk

Context

Suckfly is a China-based threat group that has been active since at least 2014.

Detection coverage

  • 135 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • Code Signing (attack-pattern)
  • Nidiran (malware)

Reports & references

  • Mandiant — Apt Groups (report)
  • Broadcom/Symantec — Viewdocument (report)
  • Broadcom/Symantec — Viewdocument (report)
  • MITRE ATT&CK — G0039 (report)
  • exchange.xforce.ibmcloud.com — Suckfly Apt Aa8Af56Fd12D25C98Fc49Ca5341160Ab (report)
  • slideshare.net — Ever Present Persistence Established Footholds Seen In The Wild (report)
  • secureworks.com — Bronze Olive (report)
  • Broadcom/Symantec — Suckfly Revealing Secret Life Your Code Signing Certificates (report)
  • Broadcom/Symantec — Indian Organizations Targeted Suckfly Attacks (report)

External references