Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Groups
  3. Suckfly

Suckfly

Suckfly is a China-based threat group that has been active since at least 2014.[1]

ID: G0039
Version: 1.1
Created: 31 May 2017
Last Modified: 16 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1059.003Command and Scripting Interpreter:Windows Command Shell

Several tools used bySuckfly have been command-line driven.[2]

EnterpriseT1046Network Service Discovery

Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open.[2]

EnterpriseT1003OS Credential Dumping

Suckfly used a signed credential-dumping tool to obtain victim account credentials.[2]

EnterpriseT1553.002Subvert Trust Controls:Code Signing

Suckfly has used stolen certificates to sign its malware.[1]

EnterpriseT1078Valid Accounts

Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner.[2]

Software

References

×

[8]ページ先頭

©2009-2026 Movatter.jp