SilentRoute is a credential-stealing malware family associated with financially motivated activity tracked as Storm-2561. It has been distributed through SEO-poisoning campaigns that direct victims to fake software download sites hosting a trojanized version of SonicWall SSL VPN NetExtender. The malicious application closely imitates the legitimate VPN client, including reuse of substantial legitimate code and use of code signing to appear trustworthy, while covertly harvesting VPN authentication data entered by the user.
Its primary observed function is theft and exfiltration of usernames, passwords, and related domain information captured through the trojanized VPN client. The malware sends the stolen data to attacker-controlled infrastructure while preserving the appearance and expected behavior of the legitimate software, making detection by end users more difficult.
SilentRoute has been linked to initial access operations in which stolen VPN credentials can enable unauthorized entry into enterprise environments. The activity around its distribution aligns with broader cybercrime workflows in which access obtained through credential theft or malware delivery is monetized directly or used to support downstream intrusion activity. Observed targeting is consistent with Windows-based enterprise users seeking remote-access software, particularly organizations relying on SonicWall VPN connectivity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered via SEO-poisoned, trojanized SonicWall SSL VPN NetExtender installers. It captures VPN authentication data entered into the trojanized app and exfiltrates it to attacker infrastructure (noted as TCP/8080).
SilentRoute [[URL_b3187638_87]] 2025 年 8 月 (v. 5.135)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.