Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Silence

Also known as: Whisper Spider, Silence

Description

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.(Citation: Cyber Forensicator Silence Jan 2019)(Citation: SecureList Silence Nov 2017)

AI Analysis

· 1 week ago

Executive Summary

Silence, also known as Whisper Spider, is a financially motivated threat actor targeting financial institutions across multiple countries, including Russia, Ukraine, Belarus, Azerbaijan, Poland, and Kazakhstan. The group has been active since at least June 2016 and has compromised banking systems, ATMs, and card processing infrastructure. Their operations demonstrate a focus on extracting financial gain through sophisticated cyberattacks.

Goals & Targeting

Silence's primary motivation appears to be financial gain, targeting sectors where financial transactions and sensitive data are concentrated. Their focus on countries within Eastern Europe suggests a geographically targeted approach that may align with operational capabilities or access to specific victim bases. The group's choice of victims indicates an intent to disrupt financial services and extract monetary gains through unauthorized access to banking systems and ATMs.

Enhanced Description

Silence is a financially motivated threat actor that primarily targets financial institutions, with a geographic focus on Russia, Ukraine, Belarus, Azerbaijan, Poland, and Kazakhstan. The group was first identified in June 2016 and has since targeted various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing infrastructure. Their attacks are characterized by a combination of sophisticated malware, credential harvesting techniques, and persistence mechanisms to maintain access to compromised systems. Silence's operations have caused significant financial damage and highlighted vulnerabilities in financial sector cybersecurity.

Key Capabilities

  • Spear-phishing attacks targeting financial institutions
  • Use of malware for system compromise and credential extraction
  • Persistence techniques via registry modifications and scheduled tasks
  • Remote access tools enabling long-term access to compromised systems

MITRE ATT&CK Tactics

Credential Access
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1053.005: Scheduled Task - Using scheduled task persistence
T1113: Screen Capture - Capturing sensitive data via screen recording
T1059.007: JavaScript - Delivering payloads using JavaScript code
T1036.005: Match Legitimate Resource Name or Location - Masquerading files and processes to blend in with legitimate resources
T1204.002: Malicious File - Distributing malicious files to compromise systems

Software / Tooling

Custom malware for banking system compromise
Screen recording utilities
Registry manipulation tools
Remote access tools (RAT)

Campaigns & Victims

Silence has demonstrated a sustained focus on financial sector targets, with campaigns spanning multiple years. Their operations suggest a high level of operational discipline and technical proficiency, often employing multi-stage attack techniques to compromise secure systems. Notable past operations include attacks against major financial institutions in targeted countries, demonstrating their persistence and ability to adapt to defensive measures.

IOC Patterns

  • Spear-phishing emails targeting financial sector employees
  • Registry modifications associated with known Silence campaigns
  • Scheduled task entries for persistence
  • Screen capture activity during business hours
  • Unusual network traffic patterns from compromised systems

Recommended Actions

  • Implement strict email filtering to detect and block spear-phishing attempts.
  • Monitor for unusual system behavior, particularlyregistry changes and scheduled tasks.
  • Enhance network monitoring for signs of lateral movement or data exfiltration.
  • Regularly update and patch banking systems to mitigate known vulnerabilities.
  • Conduct user training programs to educate employees on financial sector-specific phishing tactics.

Suggested Tags

APT
Financial Fraud
Banking Sector
Eastern Europe
Spear-Phishing

Confidence Assessment

Confidence in Silence's details is medium-high, as the group has been consistently observed since 2016 with clear targeting patterns and TTPs. However, gaps remain in understanding their exact toolset, long-term strategic goals beyond financial gain, and potential affiliations. Further analysis of their campaigns and受害者could enhance understanding.

ATT&CK Techniques

Execution
9 techniques
Stealth
6 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Crowdstrike GTR2020 Mar 2020 — Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.
  2. SecureList Silence Nov 2017 — GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.
  3. Cyber Forensicator Silence Jan 2019 — Skulkin, O.. (2019, January 20). Silence: Dissecting Malicious CHM Files and Performing Forensic Analysis. Retrieved November 17, 2024.

Intel Summary

28

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

Financial Targeting
APT
Financial Fraud
Banking Sector
Eastern Europe
Spear-Phishing

Details

MITRE ID
G0091
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--d13c8a7f-740b-4efa-a232-de7d6bb05321
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.