Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false

Silence

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016.

Attribute Detail
ATT&CK ID G0091
Aliases Whisper Spider
Attribution Not stated by MITRE ATT&CK
Class ecrime
Active since
ATT&CK entry created 2019-05-24
Techniques mapped 31

Attribution — as claimed

Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.

Known TTPs

Technique Name
T1003.001 LSASS Memory
T1018 Remote System Discovery
T1021.001 Remote Desktop Protocol
T1027.010 Command Obfuscation
T1036.005 Match Legitimate Resource Name or Location
T1053.005 Scheduled Task
T1055 Process Injection
T1059.001 PowerShell
T1059.003 Windows Command Shell
T1059.005 Visual Basic
T1059.007 JavaScript
T1070.004 File Deletion

(First 12 of 31 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Lapsus — similarly attributed-linked actor, same attribution class
  • Scattered Spider — similarly attributed-linked actor, same attribution class
  • Akira — similarly attributed-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0091 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.