Silence

MITRE ATT&CK: G0091 View on attack.mitre.org

Aliases: Whisper Spider, Silence, WHISPER SPIDER

First seen
2016-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
team
Actor type
criminal
Related IoCs
18 (7 malicious)
Last IoC activity
2026-09-02 00:35:52
Profile updated
2026-07-07 11:49:25

Targeted industries: financial-services

Targeted regions: country_code:ru country_code:ua country_code:by country_code:az country_code:pl country_code:kz

Context

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to Silence (G0091). The 7 most recently updated:

TypeIndicatorUpdatedSources
hostname rprotecruuio.com 2026-09-02 2
hostname nomoresense.com 2026-08-24 2
hostname midnigthwaall.com 2026-07-21 1
hostname files-gate.com 2026-07-08 1
hostname bluespiredice.com 2026-06-28 2
hostname listofword.com 2026-05-18 1
hostname cdn-backdl.com 2025-04-27 1

Detection coverage

  • 6 YARA rules
  • 812 Sigma rules

Malware & tools used

  • Scheduled Task (attack-pattern)
  • Process Injection (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Visual Basic (attack-pattern)
  • Modify Registry (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Video Capture (attack-pattern)
  • JavaScript (attack-pattern)
  • Compiled HTML File (attack-pattern)
  • Software Deployment Tools (attack-pattern)
  • Screen Capture (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Service Execution (attack-pattern)
  • External Proxy (attack-pattern)
  • Code Signing (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • LSASS Memory (attack-pattern)
  • PowerShell (attack-pattern)
  • Tool (attack-pattern)
  • File Deletion (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Malicious File (attack-pattern)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • reaqta.com — Silence Group Targeting Russian Banks (report)
  • group-ib.com — Silence (report)
  • Kaspersky — 83009 (report)
  • MITRE ATT&CK — G0091 (report)
  • web.archive.org — Silence Dissecting Malicious Chm Files And Performing Forensic Analysis (report)

External references