SilentBreak is a provisional intrusion-set name used for a highly targeted campaign active from at least September 2021 through February 2022 that prominently employed the SilentBreak toolset alongside Cobalt Strike and custom malware. The activity has not been attributed at high confidence to a known threat actor or state sponsor. The operation is notable for using Windows event logs as covert storage for encrypted shellcode that reconstructs and launches a fileless final-stage payload in memory. The intrusion chain used social engineering-based delivery in at least one observed case, followed by signed malicious stagers, DLL sideloading, process injection, and persistence through a copied WerFault executable paired with a malicious DLL. Malware in the campaign patched ETW- and AMSI-related functions to reduce visibility, used anti-detection wrappers compiled with multiple toolchains, and leveraged third-party code including BlackBone for memory patching and trampolines. Operators also tailored command-and-control infrastructure to victim environments through domain mimicry aligned to legitimate software and organizational context. Later-stage payloads included multiple RAT variants, including an HTTP-based Trojan reusing code associated with SilentBreak’s public Throwback repository and a named-pipe-based Trojan. These implants supported host fingerprinting, command execution, file operations, process enumeration, shellcode execution, code injection, screenshot capture, impersonation, privilege-related actions, and PowerShell execution. The campaign also involved in-memory loading of Mimikatz for credential harvesting. Observed tradecraft demonstrates strong defense evasion, persistence, post-exploitation, credential theft, and lateral movement capabilities. Known internal component names associated with the operation include Throwback, drx, monolith, and Slingshot.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as another actor known to use similar open-source shellcode patterns; no direct linkage to the 3CX/Gopuram activity beyond this comparison.
A highly targeted intrusion campaign using custom wrappers, event-log-resident shellcode, memory injection, DLL search-order hijacking, ETW/AMSI patching, and multiple last-stage Trojans, alongside commercial tooling associated with SilentBreak and Cobalt Strike.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.