SilverTerrier is a researcher and law-enforcement designation for a Nigerian cybercrime ecosystem centered on business email compromise (BEC) and related financially motivated fraud. The name has been used to describe a broad collection of West African, primarily Nigerian, actors and sub-groups rather than a single tightly unified intrusion set. Reporting has associated the ecosystem with hundreds of distinct actors or cells and large-scale targeting of organizations worldwide. SilverTerrier operations primarily focus on BEC, including vendor email compromise, mailbox takeover, fraudulent payment diversion, and gift-card fraud. The ecosystem has targeted thousands of organizations globally and has shown sustained activity against businesses in the United States and Western Europe, as well as victims across many other countries. Observed targeting has included high-technology, wholesale, and manufacturing organizations, alongside broad enterprise victimization across multiple sectors. A defining characteristic of SilverTerrier is the routine use of commodity malware to support fraud operations. Actors linked to this ecosystem have used information stealers and remote access trojans to harvest credentials, monitor victim communications, collect business documents, and improve the timing and plausibility of fraudulent payment requests. Malware families repeatedly associated with SilverTerrier include NanoCore, Remcos, NetWire, DarkComet, LuminosityLink, Imminent Monitor, Quasar, njRAT, Adwind, Hworm, Agent Tesla, LokiBot, Pony, PredatorPain, AzoRult, Zeus, Atmos, ISR Stealer, ISpySoftware, and KeyBase. NanoCore has been described as a particularly common tool within the ecosystem, and SilverTerrier actors have also used crypters and obfuscation to evade antivirus detection. SilverTerrier tradecraft includes phishing-based initial access, credential theft, keylogging, remote access, surveillance of ongoing business conversations, and exfiltration of victim data used to enable downstream fraud. Some clusters linked to the ecosystem have used HTTP for command-and-control communications, and reporting has also tied SilverTerrier-associated activity to mail-protocol-based command-and-control in malware-enabled campaigns. Campaigns attributed or linked behaviorally to the ecosystem have used localized social-engineering lures, current-events themes such as COVID-19, and deceptive attachments or archives to infect corporate users. Law-enforcement actions in Nigeria, including INTERPOL-supported operations such as Falcon II and Operation Delilah, have targeted suspected SilverTerrier members and facilitators. Arrests and forensic seizures linked to these operations indicate involvement in large-scale victim targeting, possession of extensive stolen credentials, and active monitoring of company-client communications to divert funds at the point of transaction. SilverTerrier is best understood as a financially motivated Nigerian BEC syndicate ecosystem with multiple sub-groups and overlapping operational clusters rather than a single monolithic actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the broader West African cybercrime ecosystem to which the BlackToad campaign is linked.
Referenced as a threat actor associated with this outbound SMB traffic detection analytic.
Listed as an associated threat actor in the detection annotation.
Referenced as a threat actor associated with web protocols for command-and-control activity in the detection annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.