AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Suckfly
Aliases: None listed
Suckfly is a China-based threat group that has been active since at least 2014.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idModule 11 — Mobile and thick-client security
Red Team & Offensive Security · explicit-namePrompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchModule 2 — Asset, service, identity, and exposure context
Blue Team & Defensive Security · topic-matchFile identity, containers, and executable formats
Malware Analysis & Reverse Engineering · topic-matchAndroid malware and mobile application behavior
Malware Analysis & Reverse Engineering · topic-matchIdentity, authorization, tenancy, and human approval
AI Security · topic-matchModule 5 — Threat hunting
Blue Team & Defensive Security · topic-matchModule 8 — Network defense, protocol analysis, and NDR
Blue Team & Defensive Security · topic-matchExploitability validation and laboratory exploit engineering
Vulnerability Research & Exploit Development · topic-match