created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false
Silence
Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0091 |
| Aliases | Whisper Spider |
| Attribution | Not stated by MITRE ATT&CK |
| Class | ecrime |
| Active since | — |
| ATT&CK entry created | 2019-05-24 |
| Techniques mapped | 31 |
Attribution — as claimed
Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.
Known TTPs
| Technique | Name |
|---|---|
T1003.001 |
LSASS Memory |
T1018 |
Remote System Discovery |
T1021.001 |
Remote Desktop Protocol |
T1027.010 |
Command Obfuscation |
T1036.005 |
Match Legitimate Resource Name or Location |
T1053.005 |
Scheduled Task |
T1055 |
Process Injection |
T1059.001 |
PowerShell |
T1059.003 |
Windows Command Shell |
T1059.005 |
Visual Basic |
T1059.007 |
JavaScript |
T1070.004 |
File Deletion |
(First 12 of 31 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Lapsus — similarly attributed-linked actor, same attribution class
- Scattered Spider — similarly attributed-linked actor, same attribution class
- Akira — similarly attributed-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0091 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.