Full Report
Group-IB has exposed the attacks committed by Silence cybercriminal group.
Analysis Summary
# Threat Actor: Silence
## Attribution & Identity
* **Actor Name:** Silence
* **Actor Type:** Cybercriminal Group (Financially Motivated)
* **Known Aliases:** None mentioned in the provided text.
* **General Profile:** A highly persistent and evolving criminal group specializing in sophisticated attacks against financial infrastructure.
## Activity Summary
The group transitioned from failed attempts in 2016 to highly successful thefts between 2017 and 2018. Notable operations include:
* **July/August 2016:** Repeated attempts to compromise the Russian interbank transaction system (AWS CBR).
* **October 2017:** First confirmed successful ATM "jackpotting" theft, netting over $100,000.
* **February 2018:** Successful attack on card processing systems, resulting in a loss of over $550,000.
* **April 2018:** Further ATM withdrawals totaling approximately $150,000 using refined, bug-free versions of their proprietary tools.
## Tactics, Techniques & Procedures
* **Screen Monitoring:** Downloading specialized software to capture screenshots and video streams of operator workstations to learn bank internal processes.
* **Initial Access & Persistence:** Compromising bank servers to maintain long-term access, even returning a month after a failed attempt.
* **DDoS for Distraction/Utility:** Using Perl-based IRC bots and public IRC chats for Command and Control (C2) and conducting DDoS attacks.
* **ATM Jackpotting:** Orchestrating physical withdrawals from ATMs via compromised internal bank infrastructure.
* **Card Processing Manipulation:** Attacking the processing layer to authorize fraudulent withdrawals through counterpart bank ATMs.
* **Anti-Forensics:** While the group attempts to hide, they often benefit from victim IT teams accidentally deleting logs during cleanup.
## Targeting
* **Sectors:** Financial Services, Banking, Interbank Transaction Systems, ATM Networks.
* **Geography:** Extensive global footprint covering 25+ countries across Central/Western Europe, Africa, and Asia. Specific mentions include:
* **CIS/EE:** Kyrgyzstan, Armenia, Georgia, Uzbekistan, Russia.
* **Europe:** Germany, Latvia, Czech Republic, Romania, Cyprus, Greece, Switzerland, Austria, Great Britain, Serbia.
* **Asia/Middle East:** Taiwan, Malaysia, Vietnam, Hong Kong, Israel, Turkey.
* **Africa:** Kenya.
* **Victims:** Commercial banks and interbank transaction systems (AWS CBR).
## Tools & Infrastructure
* **Malware:**
* **Proprietary Trojan:** Custom-built tools (refined by April 2018 to be stable and lightweight).
* **Perl IRC Bot:** Used for DDoS and communication.
* **Screen Capture Tool:** Specifically used for surveillance of bank employees.
* **Infrastructure:**
* **C2:** Public IRC chats utilized for controlling Trojans.
* **Interbank Systems:** Targeted the AWS CBR (Russian interbank system).
## Implications
Silence represents a disciplined threat actor that learns from failure. Their ability to return to the same victim within 30 days of a failed breach demonstrates high persistence. The evolution of their toolset—from buggy, feature-heavy malware to streamlined, stable versions—indicates a professionalization of their development cycle. Their shift from targeting interbank transfers to card processing and ATM infrastructure shows flexibility in how they monetize network access.
## Mitigations
* **Log Preservation:** IT and security teams must be trained to preserve forensic evidence (logs and artifacts) during the remediation phase to prevent accidental deletion of attacker traces.
* **Segregation of Duties:** Implement strict controls and monitoring for systems involved in interbank transactions (e.g., AWS CBR) and card processing.
* **Endpoint Monitoring:** Deploy EDR (Endpoint Detection and Response) to detect unauthorized screen-capturing software and IRC-based communication.
* **ATM Security:** Enhance monitoring of ATM controller communications and implement anomalies detection for large-scale, coordinated withdrawals.
* **Threat Hunting:** Conduct regular compromise assessments, specifically looking for indicators of lateral movement from general office networks to critical financial segments.