THREAT_ACTOR · G0091
Silence
Also known as: Silence, Whisper Spider
Profile
Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.
MITRE ATT&CK ↗Techniques
28 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1027.010 Command ObfuscationT1036.005 Match Legitimate Resource Name or LocationT1053.005 Scheduled TaskT1055 Process InjectionT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.007 JavaScriptT1070.004 File DeletionT1072 Software Deployment ToolsT1078 Valid AccountsT1090.002 External ProxyT1105 Ingress Tool TransferT1106 Native APIT1112 Modify RegistryT1113 Screen CaptureT1125 Video CaptureT1204.002 Malicious FileT1218.001 Compiled HTML FileT1547.001 Registry Run Keys / Startup FolderT1553.002 Code SigningT1566.001 Spearphishing AttachmentT1569.002 Service ExecutionT1571 Non-Standard PortT1588.002 Tool
Software
3 malware/tools attributed to this actor.
WinexeSDeleteEmpire
Related corpus activity
9,967 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Silence.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-61155 | cve | ransomware | 85 | 3 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2025-34085 | cve | — | 85 | 1 |
| cve-2023-52271 | cve | ransomware | 85 | 3 |
Showing the top 30 by severity of 9,967.