SilverFish is a name used for a sophisticated intrusion set associated with a global cyber espionage campaign. Reporting links the activity to compromises affecting dozens of Fortune 500 companies, a U.S. government entity, and multiple ministries and departments in the United States and European Union. The actor has been described as highly organized, with operational maturity consistent with sustained, around-the-clock intrusion activity. SilverFish has been reported as having strong ties to infrastructure and tradecraft associated with the SolarWinds intrusion and to criminal infrastructure linked to Evil Corp. Public analysis also connects SilverFish to SocGholish infrastructure, suggesting overlap between espionage operations and a malware delivery ecosystem that uses compromised websites and fake browser-update lures to deliver follow-on payloads. Additional reporting has noted overlap between SilverFish-linked infrastructure and activity associated with WastedLocker and later Hades ransomware operations, though the precise relationship among SilverFish, Evil Corp, and Russian state-linked operators remains analytically contested. Observed tradecraft includes drive-by compromise via fake browser updates, staged malware delivery, rapid deployment of Cobalt Strike, use of domain fronting and shadowed infrastructure, in-memory execution, privilege escalation, extensive internal reconnaissance, credential access, cloud mailbox and backup discovery, security-tool removal, and broad post-compromise operations across enterprise environments. SilverFish is best characterized as an advanced actor operating at the intersection of espionage and criminally aligned intrusion infrastructure, with notable links to SocGholish-enabled access and post-exploitation activity overlapping major ransomware campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
86 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Separate threat actor report listed in the corpus; not materially connected to the APT28-focused reference set.
Operates or is strongly associated with the SocGholish/FakeUpdates infrastructure used to redirect website visitors to fake browser update pages that deliver follow-on malware and enable ransomware intrusion chains.
Described as a sophisticated cyberespionage group linked by overlapping infrastructure and TTPs to the Wasted Locker intrusion. Reportedly used access from the SolarWinds breach and may overlap operationally with Evil Corp.
A named cyber espionage campaign/group tied in the report to a global espionage operation affecting dozens of Fortune 500 companies, a three-letter U.S. organization, and ministries/departments in the U.S. and E.U.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.