ATT&CKReferencesGroup IB Silence Sept 2018

Group IB Silence Sept 2018

Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupSilence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

T1018
Remote System Discovery
GroupSilence

Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts.

T1021.001
Remote Desktop Protocol
GroupSilence

Silence has used RDP for lateral movement.

T1036.005
Match Legitimate Resource Name or Location
GroupSilence

Silence has named its backdoor "WINWORD.exe".

T1055
Process Injection
GroupSilence

Silence has injected a DLL library containing a Trojan into the fwmain32.exe process.

T1059.001
PowerShell
GroupSilence

Silence has used PowerShell to download and execute payloads.

T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1070.004
File Deletion
GroupSilence

Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs.

T1072
Software Deployment Tools
GroupSilence

Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.

T1078
Valid Accounts
GroupSilence

Silence has used compromised credentials to log on to other systems and escalate privileges.

T1090.002
External Proxy
GroupSilence

Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5.

T1105
Ingress Tool Transfer
GroupSilence

Silence has downloaded additional modules and malware to victim’s machines.

T1106
Native API
GroupSilence

Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks.

T1112
Modify Registry
GroupSilence

Silence can create, delete, or modify a specified Registry key or value.

T1113
Screen Capture
GroupSilence

Silence can capture victim screen activity.

T1125
Video Capture
GroupSilence

Silence has been observed making videos of victims to observe bank employees day to day activities.

T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1218.001
Compiled HTML File
GroupSilence

Silence has weaponized CHM files in their phishing campaigns.

T1547.001
Registry Run Keys / Startup Folder
GroupSilence

Silence has used HKCU\Software\Microsoft\Windows\CurrentVersion\Run, HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and the Startup folder to establish persistence.

T1566.001
Spearphishing Attachment
GroupSilence

Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments.

T1569.002
Service Execution
GroupSilence

Silence has used Winexe to install a service on the remote system.

T1571
Non-Standard Port
GroupSilence

Silence has used port 444 when sending data about the system from the client to the server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.