Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Silence Group

Also known as: Silence, WHISPER SPIDER, tracked as, Evil Corp, FlawedGrace, further supporting these claims, GOLD DRAKE, Silence.Downloader, GraceWire

Description

**Targets:** Targets are located in Eastern Europe and Russia **Toolset/Malware:** Malicious CHM files, Truebot

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Critical infrastructure
Manufacturing
Education
Healthcare
Energy
Nuclear

Targeted Countries / Regions

RU
europe
UA
CA
US
AZ
KZ
BY
PL
PK
BR
MX
CN

AI Analysis

· 1 week ago

Executive Summary

The Silence Group, also known as WHISPER SPIDER, is a nation-state threat actor primarily engaged in espionage activities targeting Eastern Europe and Russia. They have demonstrated advanced capabilities in deploying malware such as Truebot and malicious CHM files to compromise victims' systems for intelligence gathering and data exfiltration.

Goals & Targeting

The Silence Group's goals appear to be primarily espionage-driven, targeting sectors such as finance, energy, and defense for sensitive data. Their geographic focus on Eastern Europe and Russia suggests a desire to influence or destabilize regional politics while gathering information on adversaries. The group likely operates under the auspices of a nation-state apparatus with interests in these regions.

Enhanced Description

The Silence Group is a sophisticated nation-state actor focused on espionage, with a primary operational focus on Eastern Europe and Russia. Their activities are characterized by the use of custom malware, such as Truebot, which enables them to gain unauthorized access to targeted systems. The group frequently employs malicious CHM files delivered via spear-phishing campaigns to compromise their victims. These campaigns are specifically designed to gather sensitive information from government, military, and financial institutions. The Silence Group's operations align with broader nation-state objectives, likely aiming to support geopolitical interests through the collection of strategic intelligence.

Key Capabilities

  • Custom malware development
  • Spear-phishing campaigns
  • Malicious file delivery (CHM/Truebot)
  • Lateral movement within networks
  • Data exfiltration techniques

MITRE ATT&CK Tactics

Initial Access
Persistence
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Truebot malware
CHM file exploits

Campaigns & Victims

The Silence Group has been observed in multiple campaigns targeting Eastern European and Russian organizations, particularly financial institutions. Their operations often involve a slow lateral movement within networks to avoid detection. Notable past activities include the deployment of sophisticated malware for long-term data collection and exfiltration. Campaign patterns suggest they are patient attackers, focusing on high-value targets to maximize their intelligence gain.

IOC Patterns

  • Spear-phishing emails with malicious CHM files
  • Malicious document downloads from compromised websites
  • C2 communication via encrypted channels

Recommended Actions

  • Implement robust email filtering and endpoint detection solutions
  • Monitor for unusual network activity indicative of lateral movement
  • Conduct regular security audits and pen testing
  • Maintain strong incident response capabilities

Suggested Tags

APT
espionage
financial-sector
nation-state

Confidence Assessment

High confidence in the assessment based on observed campaign patterns, toolset, and targeting. Some gaps remain in understanding their exact origins and complete range of capabilities.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 11 Domain 2 Filename 6 IPv4 Address 1

References

  1. blog.talosintelligence.com — Cited by web research for: Evil Corp
  2. www.fortinet.com — Cited by web research for: T1053.005
  3. www.group-ib.com — Cited by web research for: Global
  4. blog.talosintelligence.com — Cited by web research for: SolarWinds
  5. www.fortinet.com — Cited by web research for: Microsoft Teams

Intel Summary

16

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

APT
espionage
financial-sector
nation-state

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.