Also known as: Silence, WHISPER SPIDER, tracked as, Evil Corp, FlawedGrace, further supporting these claims, GOLD DRAKE, Silence.Downloader, GraceWire
**Targets:** Targets are located in Eastern Europe and Russia **Toolset/Malware:** Malicious CHM files, Truebot
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Silence Group, also known as WHISPER SPIDER, is a nation-state threat actor primarily engaged in espionage activities targeting Eastern Europe and Russia. They have demonstrated advanced capabilities in deploying malware such as Truebot and malicious CHM files to compromise victims' systems for intelligence gathering and data exfiltration.
Goals & Targeting
The Silence Group's goals appear to be primarily espionage-driven, targeting sectors such as finance, energy, and defense for sensitive data. Their geographic focus on Eastern Europe and Russia suggests a desire to influence or destabilize regional politics while gathering information on adversaries. The group likely operates under the auspices of a nation-state apparatus with interests in these regions.
Enhanced Description
The Silence Group is a sophisticated nation-state actor focused on espionage, with a primary operational focus on Eastern Europe and Russia. Their activities are characterized by the use of custom malware, such as Truebot, which enables them to gain unauthorized access to targeted systems. The group frequently employs malicious CHM files delivered via spear-phishing campaigns to compromise their victims. These campaigns are specifically designed to gather sensitive information from government, military, and financial institutions. The Silence Group's operations align with broader nation-state objectives, likely aiming to support geopolitical interests through the collection of strategic intelligence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Silence Group has been observed in multiple campaigns targeting Eastern European and Russian organizations, particularly financial institutions. Their operations often involve a slow lateral movement within networks to avoid detection. Notable past activities include the deployment of sophisticated malware for long-term data collection and exfiltration. Campaign patterns suggest they are patient attackers, focusing on high-value targets to maximize their intelligence gain.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the assessment based on observed campaign patterns, toolset, and targeting. Some gaps remain in understanding their exact origins and complete range of capabilities.
No campaigns linked yet.
No observed data linked yet.
16
Techniques
44
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics