SilverTerrier

APT / StateG0083 ↗
Techniques (MITRE ATT&CK)4
SourceMITRE ATT&CK
Attribution confidence: 50%

About the group

SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.

Techniques (MITRE ATT&CK) 4

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 574

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hash6ccc3ab2d841beb56ac6854d1a0445cf87ee746600234b53f167bac3a14fadc2AgentTeslamalwarebazaar
sha256_hashcacb33f852ed1a7206a3b87e388c2b2710c4c659afc15d9f600e1509278049b2AgentTeslamalwarebazaar
sha256_hash8315f56af982fb8f27e8df26a94e948766446e6bdd714368cb6942a663fc1c2aAgentTeslamalwarebazaar
sha256_hash36f6f8a754e37a09b84478de5df78b39be9776e1fe6d43b2272c077bd7937d98AgentTeslamalwarebazaar
sha256_hash4582612d20d8564575dc4fc21ebff73e4dbac2f0c254f5b44021896a7d97f202AgentTeslamalwarebazaar
md5_hash3d22a007f0e5878fa47d9ded220b605dAgent Teslathreatfox
sha1_hashcda5991df1a2598c1782c9eabb62755f83d6912bAgent Teslathreatfox
sha256_hash44c2f46e91c4b65b6f0c8385910af36a4255bba0fdd7bfccf2199e7a9faf19f7Agent Teslathreatfox
md5_hash00b61ee4c9907cb2dc9daadeacaa3e05Agent Teslathreatfox
sha1_hashdc1e99af1aeb99dd7366b04c12f4d8c878b3e7c1Agent Teslathreatfox
sha256_hashfd0d23011657d0185f6e4fb5fe57eb7894c9fc606b9ae5fc6b977efcb2ef1eebAgent Teslathreatfox
urlhttps://firebasestorage.googleapis.com/v0/b/a30a-33e89d-acefa0.firebasestorage.app/o/classLincoln.ps1?alt=media&token=0291b02f-3b54-4246-bc6d-6381c104d705AgentTeslaurlhaus
urlhttp://23.132.164.15/FAST/steinn.ps1AgentTeslaurlhaus
sha256_hash84de969fa7d734128d5293c458e736694b0eb42313b5d165d0ee44ca9cf888a7Agent Teslathreatfox
urlhttps://fullhouse.ae/js/TRUE.zipAgentTeslaurlhaus
urlhttp://185.29.10.68/xdZGCANqNpylcDzT208.binAgentTeslaurlhaus
urlhttp://185.29.9.42/Retslokalet.lpkAgentTeslaurlhaus
urlhttp://23.132.164.15/FAST/stein.ps1AgentTeslaurlhaus
sha256_hash202c71cccc63a9bad0c94b898a6447c2723724c7c534bfb7f2143eb6a50a2196Agent Teslathreatfox
sha256_hash39ac2c4015532e8b06bf54ecebe497ebf2652c1a55e67605fa0c2618c2735906Agent Teslathreatfox
ip:port188.132.242.67:8731DarkCometthreatfox
sha256_hash47fa97e2a70af9612d5c0a024ba4cce2163aacad465e8fc4bf6abe1bd98bbb88NanoCoremalwarebazaar
urlhttps://pub-fcf9a4a0a9f54d8b8240c682f65e12f9.r2.dev/tropvast.vbsAgentTeslaurlhaus
urlhttps://pub-a327f9d03def4b07b51dba5303fc3620.r2.dev/ojubam.pngAgentTeslaurlhaus
sha256_hash2b010a2351c9e8ee7e767abbba02dcdcc15032b20c178a3c0b00e1806e67db84AgentTeslamalwarebazaar
urlhttps://gfnstuff.pages.dev/GalacticToolsV3.exeAgent Teslathreatfox
ip:port87.243.97.168:100DarkCometthreatfox
sha256_hasha2f1061b5a9ca952c84440ea611af1df9f1871bed790ab19d8d88efd057614c1AgentTeslamalwarebazaar
ip:port188.132.242.67:8087DarkCometthreatfox
urlhttp://urbanpro.mycpanel.rs/Ringeklokkes.aafAgentTeslaurlhaus

+574 indicators in total. See them all on the IOCs page.

SilverTerrier uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →