SILENTTRINITY

MITRE ATT&CK: S0692 View on attack.mitre.org

Aliases: SILENTTRINITY

First seen
2019-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:33:06

Targeted industries: government-and-public-sector

Targeted regions: country_code:hr

Context

SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.

Detection coverage

  • 1000 Sigma rules

Malware & tools used

  • Group Policy Preferences (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Domain Groups (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Change Default File Association (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Indicator Removal (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Hidden Window (attack-pattern)
  • Windows Service (attack-pattern)
  • Local Groups (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Screen Capture (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Process Injection (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Modify Authentication Process (attack-pattern)
  • Query Registry (attack-pattern)
  • Downgrade Attack (attack-pattern)
  • Domain Account (attack-pattern)
  • Remote System Discovery (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0692 (report)
  • github.com — Silenttrinity (report)
  • securityaffairs.co — Croatia Government Silenttrinity Malware (report)

External references