APT22
Suckfly is a China-based threat group that has been active since at least 2014
China-based APT22 targets financial and technology sectors using the Nidiran backdoor.
APT22 (Suckfly/BRONZE OLIVE) is a China-based threat actor active since at least 2014. The group primarily targets financial, technology, and e-commerce sectors. They employ TTPs such as Windows Command Shell, Valid Accounts, OS Credential Dumping, Network Service Discovery, and Code Signing; their primary malware tool is Nidiran. Defenders should monitor for anomalous account activity, focus on privileged credential protection, and inspect for suspicious code-signing certificates.
Suckfly is a China-based threat group that has been active since at least 2014
Monitor for suspicious command-line activity and restrict unnecessary command-line access.
Monitor for unusual account activity and enforce strict account management policies.
Monitor for suspicious processes accessing credential stores and implement protections for credential material.
Monitor network traffic for unusual service scanning activity and limit unnecessary network exposure.
Verify the authenticity of signed code and monitor for unexpected or unauthorized code signing activity.
APT22 primarily targets the financial, technology, and e-commerce sectors.
The primary malware used by APT22 is Nidiran.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.