Also known as: Whisper Spider, Silence
Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.(Citation: Cyber Forensicator Silence Jan 2019)(Citation: SecureList Silence Nov 2017)
Executive Summary
Silence, also known as Whisper Spider, is a financially motivated threat actor targeting financial institutions across multiple countries, including Russia, Ukraine, Belarus, Azerbaijan, Poland, and Kazakhstan. The group has been active since at least June 2016 and has compromised banking systems, ATMs, and card processing infrastructure. Their operations demonstrate a focus on extracting financial gain through sophisticated cyberattacks.
Goals & Targeting
Silence's primary motivation appears to be financial gain, targeting sectors where financial transactions and sensitive data are concentrated. Their focus on countries within Eastern Europe suggests a geographically targeted approach that may align with operational capabilities or access to specific victim bases. The group's choice of victims indicates an intent to disrupt financial services and extract monetary gains through unauthorized access to banking systems and ATMs.
Enhanced Description
Silence is a financially motivated threat actor that primarily targets financial institutions, with a geographic focus on Russia, Ukraine, Belarus, Azerbaijan, Poland, and Kazakhstan. The group was first identified in June 2016 and has since targeted various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing infrastructure. Their attacks are characterized by a combination of sophisticated malware, credential harvesting techniques, and persistence mechanisms to maintain access to compromised systems. Silence's operations have caused significant financial damage and highlighted vulnerabilities in financial sector cybersecurity.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Silence has demonstrated a sustained focus on financial sector targets, with campaigns spanning multiple years. Their operations suggest a high level of operational discipline and technical proficiency, often employing multi-stage attack techniques to compromise secure systems. Notable past operations include attacks against major financial institutions in targeted countries, demonstrating their persistence and ability to adapt to defensive measures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Silence's details is medium-high, as the group has been consistently observed since 2016 with clear targeting patterns and TTPs. However, gaps remain in understanding their exact toolset, long-term strategic goals beyond financial gain, and potential affiliations. Further analysis of their campaigns and受害者could enhance understanding.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
28
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
11
Tactics