Suckfly
MITRE ATT&CK: G0039 View on attack.mitre.org
Aliases: Suckfly, BRONZE OLIVE, Group 46
- First seen
- 2014-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:32:11
Targeted industries: financial-services government-and-public-sector manufacturing technology-and-telecommunications
Targeted regions: country_code:in country_code:kr country_code:hk
Context
Suckfly is a China-based threat group that has been active since at least 2014.
Detection coverage
- 135 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Valid Accounts (attack-pattern)
- Network Service Discovery (attack-pattern)
- OS Credential Dumping (attack-pattern)
- Code Signing (attack-pattern)
- Nidiran (malware)
Reports & references
- Mandiant — Apt Groups (report)
- Broadcom/Symantec — Viewdocument (report)
- Broadcom/Symantec — Viewdocument (report)
- MITRE ATT&CK — G0039 (report)
- exchange.xforce.ibmcloud.com — Suckfly Apt Aa8Af56Fd12D25C98Fc49Ca5341160Ab (report)
- slideshare.net — Ever Present Persistence Established Footholds Seen In The Wild (report)
- secureworks.com — Bronze Olive (report)
- Broadcom/Symantec — Suckfly Revealing Secret Life Your Code Signing Certificates (report)
- Broadcom/Symantec — Indian Organizations Targeted Suckfly Attacks (report)