Silence
MITRE ATT&CK: G0091 View on attack.mitre.org
Aliases: Whisper Spider, Silence, WHISPER SPIDER
- First seen
- 2016-06-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- team
- Actor type
- criminal
- Related IoCs
- 18 (7 malicious)
- Last IoC activity
- 2026-09-02 00:35:52
- Profile updated
- 2026-07-07 11:49:25
Targeted industries: financial-services
Targeted regions: country_code:ru country_code:ua country_code:by country_code:az country_code:pl country_code:kz
Context
Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to Silence (G0091). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | rprotecruuio.com | 2026-09-02 | 2 |
| hostname | nomoresense.com | 2026-08-24 | 2 |
| hostname | midnigthwaall.com | 2026-07-21 | 1 |
| hostname | files-gate.com | 2026-07-08 | 1 |
| hostname | bluespiredice.com | 2026-06-28 | 2 |
| hostname | listofword.com | 2026-05-18 | 1 |
| hostname | cdn-backdl.com | 2025-04-27 | 1 |
Detection coverage
- 6 YARA rules
- 812 Sigma rules
Malware & tools used
- Scheduled Task (attack-pattern)
- Process Injection (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Visual Basic (attack-pattern)
- Modify Registry (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Video Capture (attack-pattern)
- JavaScript (attack-pattern)
- Compiled HTML File (attack-pattern)
- Software Deployment Tools (attack-pattern)
- Screen Capture (attack-pattern)
- Command Obfuscation (attack-pattern)
- Service Execution (attack-pattern)
- External Proxy (attack-pattern)
- Code Signing (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Valid Accounts (attack-pattern)
- Remote System Discovery (attack-pattern)
- LSASS Memory (attack-pattern)
- PowerShell (attack-pattern)
- Tool (attack-pattern)
- File Deletion (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Malicious File (attack-pattern)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- reaqta.com — Silence Group Targeting Russian Banks (report)
- group-ib.com — Silence (report)
- Kaspersky — 83009 (report)
- MITRE ATT&CK — G0091 (report)
- web.archive.org — Silence Dissecting Malicious Chm Files And Performing Forensic Analysis (report)