SilentSiphon is a multi-credential stealer suite composed of bash scripts, observed in BlueNoroff (also tracked as Sapphire Sleet/APT38) SnatchCrypto activity, including the GhostCall and GhostHire campaigns. It is delivered as part of a modular malware ecosystem alongside families such as DownTroy, CosmicDoor, and RealTimeTroy; reporting specifically states that CosmicDoor downloads the SilentSiphon stealer suite. SilentSiphon targets macOS-focused victim environments associated with Web3 and blockchain organizations, including executives, developers, and venture capital personnel. Its documented collection scope includes Apple Notes, Telegram data, browser data and browser extensions, credentials from browsers and password managers, Keychains, password-vault data, collaboration app data, cloud and DevOps secrets, and secrets stored in configuration files for services such as GitHub, AWS, Google Cloud, Microsoft Azure, Docker, Kubernetes, and OpenAI. The malware is described as supporting broad data theft beyond cryptocurrency, aligned with BlueNoroff’s campaigns against the Web3 ecosystem. No specific SilentSiphon-exclusive IOCs are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our investigation, we discovered that CosmicDoor downloads a stealer suite composed of various bash scripts, which we dubbed “SilentSiphon”.
It also downloads a bash script stealer suite named SilentSiphon. SilentSiphon is equipped to harvest data from Apple Notes, Telegram, web browser extensions, as well as credentials from browsers and password managers, and secrets stored in configuration files...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The downloader script includes a harvesting function that searches for files associated with password management applications... ZoomClutch steals macOS passwords by displaying a fake Zoom dialog... ubd.sh is the browser credentials and macOS Keychains stealer module.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-credential stealer used to harvest credentials and other sensitive data from victims in BlueNoroff campaigns.
Bash-script stealer suite that harvests notes and messenger data (e.g., Apple Notes, Telegram), browser extension data, credentials from browsers/password managers, and a wide range of developer/cloud/service secrets from configuration files (including GitHub/GitLab, cloud providers, CI/CD, containers, and Web3 ecosystems).
A modular macOS stealer suite composed of bash scripts that harvest Apple Notes, browser data, browser extensions, keychains, cloud and DevOps secrets, password-vault contents, collaboration app data, blockchain-related files, OpenAI data, and Telegram artifacts, then archives and uploads them to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.