Silence is a modular Windows malware framework and trojan associated with the financially motivated Silence cybercrime group, also tracked as GOLD WYMAN. It has been used primarily in intrusions against banks and other financial institutions in Russia, Eastern Europe, and other regions as part of theft operations including fraudulent transfers and ATM jackpotting. The malware forms part of a broader toolset that included companion components for ATM attacks, credential theft, and log removal.
Silence has commonly been delivered through spearphishing emails sent to bank employees, including campaigns using malicious document, archive, shortcut, and compiled HTML attachments, as well as exploit chains leveraging multiple Microsoft Office and Windows vulnerabilities. Once deployed, it provides operators with post-compromise access and surveillance capabilities, including screen capture and video recording used to monitor victim workflows and bank operations. The framework has also been used to download additional modules and support hands-on intrusion activity.
Operationally, Silence has relied heavily on living-off-the-land techniques and legitimate administration utilities. Reported behaviors include use of Windows API functions for execution, scheduled tasks for staging, Registry Run keys and the Startup folder for persistence, Registry modification, process injection, and artifact deletion for defense evasion. In associated operations, the threat group used compromised credentials, remote administration tools, network scanning, and remote execution utilities to move through victim environments and identify systems tied to payment processing or ATM management. Silence is best characterized as a banking trojan used in targeted financial intrusions rather than commodity crimeware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. | The exploits implanted the Silence modular malware framework on victim's systems.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. | The exploits implanted the Silence modular malware framework on victim's systems.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. | The exploits implanted the Silence modular malware framework on victim's systems.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. | The exploits implanted the Silence modular malware framework on victim's systems.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. | The exploits implanted the Silence modular malware framework on victim's systems.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. | The exploits implanted the Silence modular malware framework on victim's systems.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
$ python ta505_unpacker.py -uf tafof_silence.bin ... |--> Loaded Packed Exe Data: tafof_silence.bin
The exploits implanted the Silence modular malware framework on victim's systems.
In November 2017, Kaspersky reporeted on a new campaign that was targeting banks in Russia, Armenia and Malaysia for theft. The attack is similar to historical GOLD LOCUST (Carbanak) activity in that GOLD WYMAN uses spearphishes to target specific bank employees and deploys the Silence trojan, which includes functionality for screen video recording software, to record and monitor their activities.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack is similar to historical GOLD LOCUST (Carbanak) activity in that GOLD WYMAN uses spearphishes to target specific bank employees and deploys the Silence trojan...
Researchers say the group was very efficient at crafting spear-phishing emails. These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174.
These spear-phishing emails used exploits for the following Windows and Office vulnerabilities CVE-2017-0199, CVE-2017-11882+CVE-2018-0802, CVE-2017-0262, CVE-2017-0263, and CVE-2018-8174. The exploits implanted the Silence modular malware framework on victim's systems.
"Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe"; numerous other examples describe malware/tools that "modify registry keys/values" for persistence, configuration storage, defense evasion, and credential access.
Threat Actors make use of packers when distributing their malware as they remain an effective way to evade detection and to make them more difficult to analyze.
“DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files… actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe … has used legitimate names and locations for files to evade defenses.”
"Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe"; numerous other examples describe malware/tools that "modify registry keys/values" for persistence, configuration storage, defense evasion, and credential access.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware capable of capturing victim screen activity.
Banking malware distributed through varied malicious email attachment formats.
Final payload recovered from a TA505-packed sample.
A modular malware framework used by the Silence cybercrime group to compromise bank networks after spear-phishing, support reconnaissance and lateral movement, and enable follow-on attacks against financial institutions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.