Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Suckfly

Also known as: G0039, Suckfly, BRONZE OLIVE, Group 46

Description

Suckfly is a China-based threat group that has been active since at least 2014. (Citation: Symantec Suckfly March 2016)

Goals & Targeting

Targeted Countries / Regions

IN
CN
KR

AI Analysis

· 1 week ago

Executive Summary

Suckfly is a China-based threat group active since at least 2014, primarily engaged in espionage activities targeting India, China, and South Korea. The group has demonstrated significant operational persistence and focuses on infiltrating government, defense, and critical infrastructure sectors to gather sensitive information.

Goals & Targeting

Suckfly's primary objective appears to be espionage, targeting sectors such as government, defense, and telecommunications in India, China, and South Korea. The group likely seeks to acquire sensitive geopolitical information, intellectual property, and communications data to support Chinese strategic interests. Their focus on Asia-Pacific countries suggests a regional or state-sponsored mandate.

Enhanced Description

Suckfly, also known as G0039, BRONZE OLIVE, or Group 46, is a sophisticated cyberespionage group with suspected ties to Chinese interests. The group has been observed since at least 2014 and has targeted diplomatic entities, defense organizations, and telecommunications companies in India, China, and South Korea. Suckfly's activities are characterized by persistence and technical proficiency, employing tailored tools such as Nidiran for credential dumping. Their operations suggest a focus on long-term access to enable data exfiltration on an industrial scale. While specific campaign details remain scarce, the group's ability to maintain presence over extended periods underscores its intent to gather strategic intelligence.

Key Capabilities

  • Espionage
  • Persistent network presence
  • Credential dumping via custom tools (e.g., Nidiran)
  • CodeSigning for tool deployment
  • Windows Command Shell usage

MITRE ATT&CK Tactics

Credential Access
Discovery
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1003
T1553.002
T1059.003
T1046
T1078

Software / Tooling

Nidiran
Custom credential-dumping tools

Campaigns & Victims

Suckfly has conducted multiple campaigns targeting government and corporate entities. While specific details are limited, the group's campaigns suggest a long-term adversarial engagement strategy, often deploying custom tools for persistence and data exfiltration. The group's ability to remain undetected for prolonged periods indicates advanced tradecraft.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Backdoored Office documents
  • Network lateral movement using Windows Command Shell
  • Use of custom credential-dumping tools

Recommended Actions

  • Implement strict email filtering and DMARC policies to detect phishing attempts.
  • Monitor for signs of credential dumping and unauthorized access in Active Directory environments.
  • Segment critical networks and apply micro-segmentation to limit lateral movement.
  • Deploy endpoint detection and response (EDR) solutions to identify异常processes and TTPs.

Suggested Tags

espionage
nation-state
asia-pacific
government-targeting

Confidence Assessment

Moderate confidence in Suckfly's espionage activities and nation-state affiliations, with limited visibility into exact targeting patterns or the full extent of their capabilities. Further reporting on campaign specifics and toolsets would enhance understanding.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Symantec Suckfly March 2016 — DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.
  2. Symantec Suckfly May 2016 — DiMaggio, J. (2016, May 17). Indian organizations targeted in Suckfly attacks. Retrieved August 3, 2016.

Intel Summary

5

Techniques

8

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT
espionage
nation-state
asia-pacific
government-targeting

Details

MITRE ID
G0039
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--5cbe0d3b-6fb1-471f-b591-4b192915116d
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.