SilverFish is a Russian-linked cyberespionage group known for exploiting the SolarWinds breach.
Analyst brief
SilverFish is assessed as a Russian-linked cyberespionage group known to have exploited the SolarWinds breach as an attack vector. The group primarily targets government entities, critical infrastructure organizations, and large corporations, with links to Wasted Locker ransomware and Evil Corp indicating dual espionage and financial motivations. Key TTPs include supply chain attacks, internal network propagation, and ransomware deployment, with possible ties to banking trojans like Dridex due to the Evil Corp connection. Defenders should prioritize monitoring for supply chain risks, unusual authentication attempts, and anomalous lateral movement within the network.
SilverFish
unknown
SilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an attack vector. SilverFish has been linked to the Wasted Locker ransomware and has displayed a high level of skill and organization in their cyber operations. There are also connections between SilverFish and the threat actor Evil Corp, suggesting a possible evolution or collaboration between the two groups.