logo

Suckfly: Revealing the secret life of your code signing certificates | Symantec Connect Community

ID: ad865884-f5f7-418f-9099-90bae29ad637

STIX ID: report--ad865884-f5f7-418f-9099-90bae29ad637

Threat Score

70/100

Uploaded: 2026-08-21

Published Date: 2016-03-16

Last Modified Date: 2016-03-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details the Suckfly APT group's use of stolen code-signing certificates to sign malware and tools, enabling targeted cyberespionage across industries; it traces certificate theft, distribution, and use, describes a custom backdoor (Nidiran) delivered through an OLE vulnerability exploit, and calls for strong certificate protection and revocation practices.