THREATOPS Actor Dossier
LIVE ← Dashboard

Silence

G00913 reports
aliases · Silence · Whisper Spider
Export dossier:
3
Reports
12
Techniques
8
Tactics
2
Countries
57%
Hunt coverage
2
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1557 (Adversary-in-the-Middle), T1213.002 (Sharepoint), T1590.005 (IP Addresses).
  • Primary targeting: US, AU.
  • Resurgent after a quiet period: 1 report(s) in last 30d vs 0 prior (+100%).
  • Recent movement: 1 new technique(s), 4 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 57% of 14 observed techniques (6 gap(s)).
  • Assessment confidence: medium (62).

Activity & trend

ResurgentLast 30d: 1 vs 0 prior (+100%)· first reported 2026-02-02 · last 2026-09-11
0
7d
1
30d
1
90d
3
All
0.1
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
AML.T0042
Dropped (90d+)
T1557T1213.002T1590.005T1586.002T1684T1585.002T1589.002T1593.002T1589.003T1020T1098.005T1059.001
New infrastructure
user@victim.comvictim@victim.comattacker@evil-corp.comattacker.com

Vulnerabilities in this actor's reporting · 1

Overview

Analyst triage
Intelligence summary

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.(Citation: Cyber Forensicator Silence Jan 2019)(Citation: SecureList Silence Nov 2017)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected