Financially motivated Silence group targets Russian banks and organizations across 25+ countries with credential theft and cyber intrusions.
Analyst brief
Silence group (WHISPER SPIDER) is a financially motivated cybercriminal group active since 2016, primarily targeting Russian banks but expanding operations to over 25 countries. They use spearphishing attachments for initial access, followed by Scheduled Tasks, Visual Basic scripts, and Process Injection to steal credentials from LSASS Memory. Defenders should focus on monitoring suspicious VBA macros, LSASS access attempts, C2 traffic over non-standard ports, and the use of tools like Empire and Winexe.
Silence group
SilenceWHISPER SPIDERWhisper Spider
unknown
a relatively new threat actor that’s been operating since mid-2016
Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang had previously targeted Russian banks, Group-IB experts also have discovered evidence of the group's activity in more than 25 countries worldwide. Group-IB has published its first detailed report on tactics and tools employed by Silence. Group-IB security analysts' hypothesis is that at least one of the gang members appears to be a former or current employee of a cyber security company. The confirmed damage from Silence activity is estimated at 800 000 USD.
Silence is a group of Russian-speaking hackers, based on their commands language, the location of infrastructure they used, and the geography of their targets (Russia, Ukraine, Belarus, Azerbaijan, Poland, and Kazakhstan). Although phishing emails were also sent to bank employees in Central and Western Europe, Africa, and Asia). Furthermore, Silence used Russian words typed on an English keyboard layout for the commands of the employed backdoor. The hackers also used Russian-language web hosting services.