SilverTerrier is a researcher and law-enforcement designation for a Nigerian cybercrime ecosystem centered on business email compromise (BEC) and related fraud. Rather than a single tightly bounded intrusion set, it refers to a broad collection of Nigerian actors and sub-groups engaged in financially motivated email fraud, account compromise, and malware-assisted social engineering at global scale. Reporting has described the ecosystem as comprising hundreds of distinct actors or groups and as targeting thousands of organizations worldwide. SilverTerrier operations primarily focus on BEC, including vendor email compromise, mailbox compromise, conversation hijacking, and payment diversion. The actors commonly use phishing and social-engineering lures tied to invoices, purchase orders, payment slips, shipping issues, health themes, and other business-relevant pretexts to gain access to accounts or induce fraudulent payments. Gift-card fraud and other low-friction monetization schemes have also been associated with Nigerian BEC activity overlapping this ecosystem. A defining characteristic of SilverTerrier is its routine use of commodity malware to improve victim profiling and fraud success rates. Malware families repeatedly associated with the ecosystem include NanoCore, NetWire, Remcos, njRAT, DarkComet, Quasar, Adwind, LuminosityLink, Imminent Monitor, H-Worm, Agent Tesla, LokiBot, Pony, PredatorPain, Zeus, AzoRult, Atmos, ISpySoftware, ISR Stealer, and related stealers and remote access trojans. These tools are used to steal credentials, monitor victims, capture business communications, and support follow-on fraud. The ecosystem also makes extensive use of crypters and obfuscation to evade antivirus detection, and some observed clusters have used HTTP-based command-and-control for remote access tooling. SilverTerrier has targeted organizations across multiple sectors, with especially strong reporting on technology, wholesale, and manufacturing victims. Activity has been observed globally, including campaigns affecting organizations in the United States, the United Kingdom, Singapore, Japan, and numerous other countries. Law-enforcement investigations have also linked associated suspects to operations spanning West Africa, including Ghana and Gambia. Operationally, SilverTerrier actors have demonstrated credential theft, keylogging through associated malware, persistence via RAT deployment, data exfiltration, and post-compromise monitoring of business communications to time fraudulent fund-diversion attempts. Some clusters linked to the ecosystem have used compromised personal or vendor email accounts, look-alike webmail accounts, and harvested contact lists to expand targeting. The ecosystem is best understood as organized cybercrime focused on financial fraud rather than espionage or destructive activity. SilverTerrier has been the subject of major international disruption efforts. Joint investigations and arrests by Nigerian authorities and INTERPOL, supported by private-sector partners, have tied multiple suspects to large-scale BEC activity, including possession of extensive stolen credentials and active monitoring of company-client communications for transaction interception. These actions reinforced the assessment that SilverTerrier represents a substantial Nigerian BEC syndicate and broader criminal network rather than an isolated group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the broader West African cybercrime ecosystem to which the BlackToad campaign is linked.
Referenced as a threat actor associated with this outbound SMB traffic detection analytic.
Listed as an associated threat actor in the detection annotation.
Referenced as a threat actor associated with web protocols for command-and-control activity in the detection annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.