THREAT_ACTOR · G0039
Suckfly
Also known as: Suckfly
Profile
Suckfly is a China-based threat group that has been active since at least 2014.
MITRE ATT&CK ↗Techniques
5 ATT&CK techniques attributed to this actor.
Software
1 malware/tools attributed to this actor.
Nidiran
Related corpus activity
2,348 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Suckfly.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2016-0638 | cve | phishing | 85 | 1 |
| cve-2025-61155 | cve | ransomware | 85 | 3 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2025-1055 | cve | ransomware | 85 | 3 |
| cve-2021-27137 | cve | — | 85 | 8 |
| cve-2017-17215 | cve | — | 85 | 2 |
| cve-2023-52271 | cve | ransomware | 85 | 3 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4 | hash | phishing | 80 | 2 |
| 9c44bc9373377831c45dd0ac2661a28e | hash | — | 80 | 3 |
| 01e3dce00ea45829bd9f6a583004976ac63973a0 | hash | cryptojacking | 80 | 1 |
| 123e80a34508c4dede7cc70e76931fcc | hash | — | 80 | 3 |
| d35695f2366a43628231e73ffa83ca106306a8fa | hash | — | 80 | 2 |
| f96bcd875836da89800912de1e557891697c7cf4 | hash | — | 80 | 2 |
| b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0 | hash | — | 80 | 3 |
| fe0161fb8a26a0bf4afad746c7ebf89499dcd3a7 | hash | — | 80 | 2 |
| 2654c08491a0f7c4a3dfc6282de5638b | hash | — | 80 | 3 |
Showing the top 30 by severity of 2,348.