Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Threat actors
G0039
threat actor
Suckfly
Suckfly is a China-based threat group that has been active since at least 2014.
MITRE ATT&CK ↗
Linked entities · 8
uses
S0118
Nidiran
uses
T1059.003
Windows Command Shell
uses
T1078
Valid Accounts
uses
T1046
Network Service Discovery
uses
T1553.002
Code Signing
uses
T1003
OS Credential Dumping
mentions by
0a25225e394f8010
Suckfly: Revealing the secret lif…
mentions by
64b34859478bd3ba
Indian organizations targeted in …