SilverFish_Solarwinds.pdf
ID: d7f79a76-bd74-4961-a5aa-31fe62f05444
STIX ID: report--d7f79a76-bd74-4961-a5aa-31fe62f05444
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-03-18
Last Modified Date: 2021-03-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The PTI Team report details the discovery and analysis of the 'SilverFish' threat actor/campaign: a highly organized, multi-team operation targeting primarily US and EU critical infrastructure and large enterprises (≈4,720+ victims). The researchers gained access to C2 infrastructure and a traffic distribution system, observed advanced post‑exploitation tooling (Cobalt Strike, Empire, Koadic, bespoke 'Sarasota' scripts), domain‑fronting and proxying techniques, and a 'VictimTotal' sandbox used to test payloads across thousands of live enterprise hosts; the report provides extensive IOCs, timelines, and MITRE ATT&CK mappings to support detection and remediation.
