Suckfly: Revealing the secret life of your code signing certificates | Symantec Connect Community
ID: ad865884-f5f7-418f-9099-90bae29ad637
STIX ID: report--ad865884-f5f7-418f-9099-90bae29ad637
Threat Score
70/100
Uploaded: 2026-08-21
Published Date: 2016-03-16
Last Modified Date: 2016-03-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details the Suckfly APT group's use of stolen code-signing certificates to sign malware and tools, enabling targeted cyberespionage across industries; it traces certificate theft, distribution, and use, describes a custom backdoor (Nidiran) delivered through an OLE vulnerability exploit, and calls for strong certificate protection and revocation practices.
