CSIDB logo
Threat actor

SilverTerrier

Attribution profile

Type
Crime Syndicate
Location
Nigeria
Known incidents
3 incidents
First seen
2019-03-15
Last seen
2021-02-03
Updated
2026-08-01 19:45
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

SilverTerrier is a Nigerian‑based cybercrime group also known by its alias SilverTerrier. The group has been active since at least 2014. Public reporting indicates it primarily targets organizations in the technology, higher education, and manufacturing sectors. Its activities have been observed across multiple continents, prompting cooperation among law‑enforcement agencies in four regions.

In February 2021 SilverTerrier carried out a business‑email‑compromise attack against the Chilean state‑owned oil company ENAP. The attackers impersonated a supplier and requested a change to the supplier’s bank account details, which ENAP processed before the transaction was blocked by the recipient bank. After the failed fraud attempt the group gained unauthorized access to ENAP’s email system and sent hundreds of spam messages from a director’s mailbox containing links to external sites. This episode shows that SilverTerrier’s typical initial access vector is a spoofed email that mimics a trusted correspondent, followed by exploitation of compromised credentials for further abuse.

Law‑enforcement authorities in Nigeria have arrested individuals linked to the group, including an alleged senior member and, in a separate operation, eleven suspects believed to belong to SilverTerrier. These arrests were reported by the Nigerian Police Force and the Organized Crime and Corruption Reporting Project. The group is estimated to have exposed more than fifty thousand potential victims to fraud schemes over its operational history. No public source attributes SilverTerrier to any state sponsor or larger criminal consortium.

Collectively, the available evidence describes SilverTerrier as a financially motivated cybercriminal outfit that relies on social engineering and credential abuse to pursue illicit gain, with the reported incidents not referencing any malware usage. Its focus on specific industry sectors and repeated use of business‑email‑compromise tactics illustrate a consistent operational pattern. Ongoing investigative actions suggest that the group remains active despite increased scrutiny from international authorities. This summary reflects only the facts explicitly stated in the supplied sources.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB