Silence

G0091

Threat group.View on attack.mitre.org

About this group

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1003.001
LSASS Memory

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

T1018
Remote System Discovery

Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts.

T1021.001
Remote Desktop Protocol

Silence has used RDP for lateral movement.

T1027.010
Command Obfuscation

Silence has used environment variable string substitution for obfuscation.

T1036.005
Match Legitimate Resource Name or Location

Silence has named its backdoor "WINWORD.exe".

T1053.005
Scheduled Task

Silence has used scheduled tasks to stage its operation.

T1055
Process Injection

Silence has injected a DLL library containing a Trojan into the fwmain32.exe process.

T1059.001
PowerShell

Silence has used PowerShell to download and execute payloads.

T1059.003
Windows Command Shell

Silence has used Windows command-line to run commands.

T1059.005
Visual Basic

Silence has used VBS scripts.

T1059.007
JavaScript

Silence has used JS scripts.

T1070.004
File Deletion

Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs.

T1072
Software Deployment Tools

Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.

T1078
Valid Accounts

Silence has used compromised credentials to log on to other systems and escalate privileges.

T1090.002
External Proxy

Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5.

View all 28 procedure examples

Software3

Campaigns0

None recorded.

References2

  1. Cyber Forensicator Silence Jan 2019 Open source
    Skulkin, O.. (2019, January 20). Silence: Dissecting Malicious CHM Files and Performing Forensic Analysis. Retrieved November 17, 2024.
  2. SecureList Silence Nov 2017 Open source
    GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.