Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupSilence | Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe. |
| T1018 Remote System Discovery |
GroupSilence | Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts. |
| T1021.001 Remote Desktop Protocol |
GroupSilence | Silence has used RDP for lateral movement. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSilence | Silence has named its backdoor "WINWORD.exe". |
| T1055 Process Injection |
GroupSilence | Silence has injected a DLL library containing a Trojan into the fwmain32.exe process. |
| T1059.001 PowerShell |
GroupSilence | Silence has used PowerShell to download and execute payloads. |
| T1059.003 Windows Command Shell |
GroupSilence | Silence has used Windows command-line to run commands. |
| T1070.004 File Deletion |
GroupSilence | Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs. |
| T1072 Software Deployment Tools |
GroupSilence | Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs. |
| T1078 Valid Accounts |
GroupSilence | Silence has used compromised credentials to log on to other systems and escalate privileges. |
| T1090.002 External Proxy |
GroupSilence | Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5. |
| T1105 Ingress Tool Transfer |
GroupSilence | Silence has downloaded additional modules and malware to victim’s machines. |
| T1106 Native API |
GroupSilence | Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks. |
| T1112 Modify Registry |
GroupSilence | Silence can create, delete, or modify a specified Registry key or value. |
| T1113 Screen Capture |
GroupSilence | Silence can capture victim screen activity. |
| T1125 Video Capture |
GroupSilence | Silence has been observed making videos of victims to observe bank employees day to day activities. |
| T1204.002 Malicious File |
GroupSilence | Silence attempts to get users to launch malicious attachments delivered via spearphishing emails. |
| T1218.001 Compiled HTML File |
GroupSilence | Silence has weaponized CHM files in their phishing campaigns. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupSilence | Silence has used |
| T1566.001 Spearphishing Attachment |
GroupSilence | Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments. |
| T1569.002 Service Execution |
GroupSilence | Silence has used Winexe to install a service on the remote system. |
| T1571 Non-Standard Port |
GroupSilence | Silence has used port 444 when sending data about the system from the client to the server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.