Skip to main content
Mallory
🇳🇬 NG20 malware families

SilverTerrier

Also known asSilverTerrier

SilverTerrier is the codename used by researchers and law enforcement for a Nigerian-based cybercrime syndicate and broader ecosystem involved in business email compromise (BEC) fraud. The content describes SilverTerrier as a collective name for multiple Nigerian groups or actors, with reporting citing more than 400 unique actors or groups, and identifies it as originating from Nigeria. Palo Alto Networks Unit 42 is cited as tracking Nigerian BEC actors under this codename since 2014. SilverTerrier has been accused of targeting thousands of organizations worldwide and harming thousands of companies globally through BEC scams. The group’s activity centers on BEC, including monitoring business communications and diverting funds when transactions are about to occur. Reported targeting includes organizations worldwide, with sectors such as high-tech, wholesale, and manufacturing specifically noted in Unit 42 reporting. The content also describes COVID-19-themed scam activity, including fake PPE orders, shipping-delay notices, and vaccine-related messages carrying malware. SilverTerrier is repeatedly associated with malware-assisted BEC operations. The content states that the group used information stealers and increasingly remote access trojans to improve targeting and fraud success. Malware families explicitly linked to SilverTerrier in the content include NanoCore, njRAT, NetWire, DarkComet, LuminosityLink, Remcos, ImminentMonitor, Quasar, Adwind, Hworm, AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus. NanoCore is described as the RAT of choice for SilverTerrier and as the most frequently seen RAT in 2018. The group also used crypters to encrypt, obfuscate, and modify malware to evade antivirus detection. Tactics and techniques directly mentioned in the content include use of HTTP for command-and-control communications, use of mail protocols/FTP in detections and ATT&CK annotations, and use of remote access tools. One campaign behaviorally linked to elements of the SilverTerrier ecosystem involved Thai-language phishing lures themed as payment slips, a WinRAR self-extracting archive using a deceptive .pdf.scr double extension, a Visual Basic script that temporarily disrupted connectivity via ipconfig, a renamed AutoIt3 interpreter, RC4-decrypted Remcos configuration data, and dynamic DNS-backed command-and-control infrastructure. That campaign was tracked as BlackToad and linked behaviorally to the SilverTerrier ecosystem rather than directly attributed as SilverTerrier itself. Law enforcement reporting in the content ties SilverTerrier to multiple arrests in Nigeria. INTERPOL and the Nigerian Police Force arrested 11 alleged members of a cybercrime network in Operation Falcon II, with many suspects believed to be members of SilverTerrier. Preliminary analysis linked the suspects’ collective BEC activity to more than 50,000 targets; one suspect possessed more than 800,000 potential victim domain credentials, and another allegedly monitored conversations between 16 companies and their clients to divert funds to the gang. The content also states that in May 2022 INTERPOL announced the arrest of a 37-year-old Nigerian man regarded as the leader of the syndicate during Operation Delilah. Known aliases and related names directly mentioned in the content include only SilverTerrier. Related clusters or campaigns mentioned as linked to the ecosystem, but not stated as aliases, include BlackToad and BoredFluff.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • NG
MITRE ATT&CK

Tradecraft

23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics35 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0042
Resource Development
3 techniques
T1586
Compromise Accounts
T1586.002×2
Email Accounts
T1587
Develop Capabilities
T1587.002
Code Signing Certificates
T1588
Obtain Capabilities
T1588.004
Digital Certificates
TA0001
Initial Access
3 techniques
T1078×3
Valid Accounts
T1190
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0003
Persistence
2 techniques
T1078×3
Valid Accounts
T1112
Modify Registry
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1078×3
Valid Accounts
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.001×2
Keylogging
T1539
Steal Web Session Cookie
TA0009
Collection
4 techniques
T1056
Input Capture
T1056.001×2
Keylogging
T1114×3
Email Collection
T1123
Audio Capture
T1125
Video Capture
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001×10
Web Protocols
T1071.002×2
File Transfer Protocols
T1071.003×3
Mail Protocols
T1105
Ingress Tool Transfer
T1219×4
Remote Access Tools
T1573
Encrypted Channel
T1573.002×2
Asymmetric Cryptography
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
1 technique
T1657×2
Financial Theft
IOCS

Observables

4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping23

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal20

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables4

Domains, IPs, and hashes tied to this actor, refreshed continuously.