EtterSilent is a malicious document builder used in the cybercrime ecosystem to generate weaponized Microsoft Office files for initial malware delivery. It has been advertised on Russian-language criminal forums and adopted by multiple financially motivated threat actors as a commoditized infection component rather than a standalone payload family.
EtterSilent has been observed producing Office documents that either exploit CVE-2017-8570 or rely on malicious macros, with macro-enabled Excel variants appearing especially common. These documents frequently use social-engineering themes such as DocuSign-branded content to induce user interaction. In macro-based chains, hidden Excel 4.0 macros retrieve an external payload, write it locally, and execute it, including through living-off-the-land binaries such as regsvr32 or rundll32.
The builder has been used as an initial access mechanism in spam-driven campaigns delivering additional malware families including Trickbot, Bazar Loader, BokBot, Gozi ISFB, QBot, and Ursnif. It has been associated with activity by TA584 and with campaigns leveraging bulletproof hosting infrastructure, including services attributed to Yalishanda. EtterSilent illustrates the specialization of the criminal malware supply chain, where document builders, spam operations, hosting providers, and downstream malware operators are combined into modular intrusion workflows.
EtterSilent primarily targets Microsoft Office users on Windows environments and is best characterized as a delivery-stage malware builder enabling follow-on compromise rather than as the final payload itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The latest “product” is a malicious document builder, known in the underground as “EtterSilent,” that Intel 471 has seen leveraged by various cybercrime groups.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In early campaigns, TA584 also delivered macro-enabled Excel documents (tracked as EtterSilent)…”
1 distinct technique documented for this family, organized by ATT&CK tactic.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Macro-enabled Excel-based initial-stage payload used to facilitate installation of subsequent malware in TA584 campaigns.
Tracking name for TA584’s macro-enabled Excel document delivery mechanism used in earlier campaigns to lead to malware installation when macros are enabled.
A malicious Microsoft Office document builder used to create weaponized maldocs, including macro-based and CVE-2017-8570 exploit documents, that download and execute external payloads via Excel 4.0 macros and LOLBins such as regsvr32 or rundll32.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.