ATT&CKSoftwareSILENTTRINITY

SILENTTRINITY

S0692

Tool.View on attack.mitre.org

About this tool

SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.

Techniques used53

Procedure examples53

TechniqueProcedure example
T1003.001
LSASS Memory

SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call.

T1007
System Service Discovery

SILENTTRINITY can search for modifiable services that could be used for privilege escalation.

T1010
Application Window Discovery

SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`.

T1012
Query Registry

SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives.

T1018
Remote System Discovery

SILENTTRINITY can enumerate and collect the properties of domain computers.

T1021.003
Distributed Component Object Model

SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM.

T1021.006
Windows Remote Management

SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM.

T1033
System Owner/User Discovery

SILENTTRINITY can gather a list of logged on users.

T1041
Exfiltration Over C2 Channel

SILENTTRINITY can transfer files from an infected host to the C2 server.

T1046
Network Service Discovery

SILENTTRINITY can scan for open ports on a compromised machine.

T1047
Windows Management Instrumentation

SILENTTRINITY can use WMI for lateral movement.

T1055
Process Injection

SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process.

T1056.001
Keylogging

SILENTTRINITY has a keylogging capability.

T1056.002
GUI Input Capture

SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials.

T1057
Process Discovery

SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded.

View all 53 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. GitHub SILENTTRINITY March 2022 Open source
    Salvati, M (2019, August 6). SILENTTRINITY. Retrieved March 23, 2022.
  2. Security Affairs SILENTTRINITY July 2019 Open source
    Paganini, P. (2019, July 7). Croatia government agencies targeted with news SilentTrinity malware. Retrieved March 23, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.