GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
GroupSilence | Silence has used Windows command-line to run commands. |
| T1106 Native API |
GroupSilence | Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks. |
| T1113 Screen Capture |
GroupSilence | Silence can capture victim screen activity. |
| T1125 Video Capture |
GroupSilence | Silence has been observed making videos of victims to observe bank employees day to day activities. |
| T1204.002 Malicious File |
GroupSilence | Silence attempts to get users to launch malicious attachments delivered via spearphishing emails. |
| T1218.001 Compiled HTML File |
GroupSilence | Silence has weaponized CHM files in their phishing campaigns. |
| T1566.001 Spearphishing Attachment |
GroupSilence | Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments. |
| T1569.002 Service Execution |
GroupSilence | Silence has used Winexe to install a service on the remote system. |
| T1588.002 Tool |
GroupSilence | Silence has obtained and modified versions of publicly-available tools like Empire and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.