Silence, also tracked as Whisper Spider, is a financially motivated cybercrime group best known for intrusions targeting banks and other financial institutions, particularly in Eastern Europe and surrounding regions. The group has conducted bank-focused operations involving initial compromise, internal reconnaissance, credential theft, lateral movement, and fraudulent cash-out activity. Its tradecraft reflects a mature intrusion set oriented toward monetization rather than espionage, with a strong emphasis on understanding victim banking workflows and maintaining access long enough to enable theft. Silence has relied heavily on spearphishing with malicious attachments to gain initial execution. After compromise, the group has used PowerShell, JavaScript-based scripts, and Windows command-line utilities to stage payloads and execute follow-on actions. It has also leveraged modified versions of publicly available offensive tools, including Empire and PsExec, alongside its own malware and backdoors. Reported behavior includes process injection for stealth and execution within legitimate processes, as well as use of proxying or tunneling components to relay traffic through compromised hosts and support command-and-control operations. For persistence, Silence has used Windows autorun mechanisms including Registry Run keys in both user and machine hives and Startup folder artifacts. The group has also modified Registry values as part of persistence and system configuration changes. In victim environments, Silence has performed network discovery and mapping, including scanning to identify reachable and potentially vulnerable hosts, and has used Remote Desktop Protocol for lateral movement and interactive access. A notable aspect of Silence operations is surveillance of bank personnel and workflows. The group has been observed recording video of victims to monitor bank employees’ day-to-day activities, indicating an operational model that combines technical compromise with close observation of business processes to facilitate fraud. This aligns with broader patterns of targeting financial operations staff and studying internal procedures before attempting theft. Silence is commonly associated with the malware ecosystem bearing the same name and with the alias Whisper Spider. High-confidence reporting characterizes the group as a Russian-speaking, financially motivated threat actor rather than a nation-state espionage operator. Its activity is distinguished by targeted attacks on the financial sector, use of commodity and customized tooling, persistence through common Windows mechanisms, and post-compromise surveillance to support bank fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Mentioned only in the detection annotation metadata; no campaign activity or actor-specific behavior is described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.