Research on the financially motivated Silence threat group shows its malware toolkit evolved beyond a basic downloader into a more capable intrusion platform used after initial compromise. Analysis of downloader samples observed from 2017 through early 2019 found that newer variants added host reconnaissance, collecting system details into INFOCONTENT.TXT for upload to command-and-control infrastructure, checking operating system and antivirus products, and changing persistence mechanisms from registry Run keys to an alternative scheduled task named "Avi Capture". Later versions also expanded execution options, allowing operators to launch an EXE or register a DLL after receiving tasking from the C2 server.
Separate analysis of a lesser-documented .NET proxy attributed to Silence indicates the group also developed tooling to move traffic through compromised systems inside networks that are normally isolated from the internet. The proxy, reportedly packed with SmartAssembly, reads a configuration file, selects a connection mode, and connects to a specified C2 while optionally logging status locally. Observed and intended modes included SocksServer, DirectBackConnector, ProxyBackConnector, and authenticated proxy options such as ProxyBackConnectorWithAuth and ProxyBackConnectorWithNtlmAuth, suggesting support for lateral access and credential-aware tunneling inside victim environments as the group refined its post-compromise operations.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
In February 2019, Silence reportedly stole about $400,000 from the Russian bank Omsk IT Bank. The incident is cited in the report as one of the group's successful bank theft operations.
In August 2018, Group-IB published research on Silence that mentioned a proxy tool used to route traffic to and from infected devices on networks normally isolated from the Internet. This appears to be the earliest public reference in the provided sources to the Silence proxy capability.
In later samples observed after the late-2018 variant, the Silence downloader added antivirus process checks, alternate persistence via either a Run key or a scheduled task named "Avi Capture," and the ability to either execute an EXE or register a DLL. The samples also shifted C2 communications to a Winsock-based implementation.
By late 2018, newer Silence downloader versions had added command-line based information gathering, stored results in ProgramData\INFOCONTENT.TXT, and uploaded that file to the C2 server. These versions also changed persistence behavior and updated task parsing logic.
In October 2017, Kaspersky Securelist publicly described a Silence downloader sample at a high level. The sample functioned as an early-stage malware component that contacted C2, established registry Run-key persistence, downloaded and executed payloads, or deleted itself on command.
In July 2016, Silence carried out its first recorded attack, attempting to steal funds via Russia’s AWS CBR inter-bank transaction system. The attempt failed because the payment order was improperly prepared and bank employees suspended the transaction.
Analysis of two Silence proxy samples showed the malware was still under development: an older sample lacked code for the ProxyBackConnector case, while a newer sample implemented it. The proxy supported or was intended to support multiple traffic-routing modes, including SOCKS and NTLM-authenticated proxying.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
group-ib.com
Open sourcenorfolkinfosec.com
Open sourcenorfolkinfosec.com
Open sourcezdnet.com
Open sourcegroup-ib.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.