ATT&CKReferencesSecureList Silence Nov 2017

SecureList Silence Nov 2017

GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1106
Native API
GroupSilence

Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks.

T1113
Screen Capture
GroupSilence

Silence can capture victim screen activity.

T1125
Video Capture
GroupSilence

Silence has been observed making videos of victims to observe bank employees day to day activities.

T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1218.001
Compiled HTML File
GroupSilence

Silence has weaponized CHM files in their phishing campaigns.

T1566.001
Spearphishing Attachment
GroupSilence

Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments.

T1569.002
Service Execution
GroupSilence

Silence has used Winexe to install a service on the remote system.

T1588.002
Tool
GroupSilence

Silence has obtained and modified versions of publicly-available tools like Empire and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.