Silence Group
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Silence Group, also tracked as Silence, is a threat actor linked to Russia and known to operate since at least 2016. Public reporting identifies a core of two Russian‑speaking individuals who possess backgrounds in legitimate security work. The group is described as financially motivated, seeking monetary gain through cyber‑enabled theft. Early activity included an attempt to compromise the Russian Central Bank’s Automated Workstation Client.
While early operations focused on Russian targets, the actor later expanded its reach to financial institutions in other regions. The Bangladesh incidents of May 2019 illustrate this shift, with three private banks hit in a coordinated campaign. The actor’s objective in these cases was to obtain cash through fraudulent ATM withdrawals. No evidence points to espionage or disruption as a primary aim.
The group’s toolkit centers on several custom malware families: Silence.Downloader (also known as TrueBot), Silence.MainModule, and Silence.ProxyBot. These components are used to establish persistent access, execute remote commands, and facilitate traffic redirection via compromised hosts. In the Bangladesh attacks, the actors either installed a jackpotting toolkit called Atmosphere on the ATM network or altered transaction limits within the card‑processing system to trigger cash dispenses. Money mules, predominantly Ukrainian nationals, were recruited to physically collect the cash from compromised machines.
Infrastructure linked to the activity includes a command‑and‑control server at IP address 103.11.138.198, with connections observed as early as February 2019 prior to the cash‑out events. The prolonged network compromise allowed reconnaissance and staging before the monetary theft was executed. The Bangladesh case is frequently cited as a representative operation that demonstrates the actor’s end‑to‑end methodology from intrusion to cash‑out. No public attribution to a state sponsor or larger criminal consortium has been made beyond the individuals identified in open reporting.
Incidents
Attributed incidents are available to members.
3 incidents