Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SilverTerrier

Also known as: Nigeria

Description

SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.(Citation: Unit42 SilverTerrier 2018)(Citation: Unit42 SilverTerrier 2016)

AI Analysis

· 1 week ago

Executive Summary

SilverTerrier is a Nigerian threat group active since 2014, targeting high-tech, education, and manufacturing sectors primarily through espionage activities. They employ malware for data exfiltration and are known to use tools like NETWIRE and DarkComet.

Goals & Targeting

SilverTerrier's primary motivation is espionage, targeting sectors that hold valuable intellectual property and sensitive information. Their choice of high technology and education sectors indicates a desire to acquire advanced knowledge and data. The targeted countries may include those with significant industrial capabilities in manufacturing, particularly the US and EU nations.

Enhanced Description

SilverTerriet, a Nigerian cyber-espionage group, has been active since 2014, focusing on sectors with sensitive information such as high technology, higher education, and manufacturing. They utilize malware and malicious emails to gain unauthorized access, often aiming for long-term data collection. Their activities include targeted spear-phishing campaigns using tools like NETWIRE, DarkComet, and others. While their exact targets are unclear beyond the initial data, they have shown a steady operational pattern over several years, suggesting a focus on sustained information gathering rather than immediate financial gain.

Key Capabilities

  • Use of malware for unauthorized access
  • Spear-phishing campaigns
  • Data exfiltration

MITRE ATT&CK Tactics

Collection
Exfiltration
Financial Theft

ATT&CK Techniques

T1071.003
T1071.002
T1071.001
T1657

Software / Tooling

NETWIRE
DarkComet
NanoCore
Lokibot
Agent Tesla

Campaigns & Victims

SilverTerrier has a sustained operational presence, likely focusing on long-term data theft without prominent high-profile campaigns. Targeting of specific sectors over an extended period suggests a strategic focus on infiltrating organizations with sensitive information.

IOC Patterns

  • Spear-phishing emails
  • Malware distribution via email attachments
  • Use of malicious file transfer protocols

Recommended Actions

  • Implement multi-factor authentication (MFA)
  • Enhance email filtering to detect phishing attempts
  • Monitor network traffic for suspicious activities
  • Regularly update software and systems with security patches

Suggested Tags

APT
Espionage
HighTechnology
Manufacturing

Confidence Assessment

Moderate confidence based on available data, primarily from Unit42 reports. Limited visibility into specific campaigns or exact targets introduces some uncertainty in their full capabilities and operational nuances.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Unit42 SilverTerrier 2016 — Renals, P., Conant, S. (2016). SILVERTERRIER: The Next Evolution in Nigerian Cybercrime. Retrieved November 13, 2018.
  2. Unit42 SilverTerrier 2018 — Unit42. (2016). SILVERTERRIER: THE RISE OF NIGERIAN BUSINESS EMAIL COMPROMISE. Retrieved November 13, 2018.

Intel Summary

4

Techniques

12

Tools

0

Campaigns

77

IOCs

0

Observed Data

2

Tactics

Tags

APT
Espionage
HighTechnology
Manufacturing

Details

MITRE ID
G0083
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
N
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--76565741-3452-4069-ab08-80c0ea95bbeb
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.