Also known as: G0039, Suckfly, BRONZE OLIVE, Group 46
Suckfly is a China-based threat group that has been active since at least 2014. (Citation: Symantec Suckfly March 2016)
Targeted Countries / Regions
Executive Summary
Suckfly is a China-based threat group active since at least 2014, primarily engaged in espionage activities targeting India, China, and South Korea. The group has demonstrated significant operational persistence and focuses on infiltrating government, defense, and critical infrastructure sectors to gather sensitive information.
Goals & Targeting
Suckfly's primary objective appears to be espionage, targeting sectors such as government, defense, and telecommunications in India, China, and South Korea. The group likely seeks to acquire sensitive geopolitical information, intellectual property, and communications data to support Chinese strategic interests. Their focus on Asia-Pacific countries suggests a regional or state-sponsored mandate.
Enhanced Description
Suckfly, also known as G0039, BRONZE OLIVE, or Group 46, is a sophisticated cyberespionage group with suspected ties to Chinese interests. The group has been observed since at least 2014 and has targeted diplomatic entities, defense organizations, and telecommunications companies in India, China, and South Korea. Suckfly's activities are characterized by persistence and technical proficiency, employing tailored tools such as Nidiran for credential dumping. Their operations suggest a focus on long-term access to enable data exfiltration on an industrial scale. While specific campaign details remain scarce, the group's ability to maintain presence over extended periods underscores its intent to gather strategic intelligence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Suckfly has conducted multiple campaigns targeting government and corporate entities. While specific details are limited, the group's campaigns suggest a long-term adversarial engagement strategy, often deploying custom tools for persistence and data exfiltration. The group's ability to remain undetected for prolonged periods indicates advanced tradecraft.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in Suckfly's espionage activities and nation-state affiliations, with limited visibility into exact targeting patterns or the full extent of their capabilities. Further reporting on campaign specifics and toolsets would enhance understanding.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
5
Techniques
8
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics