Silent Team is a cybercriminal extortion group that emerged in 2025 and has been associated with leak-based, exfiltration-first operations rather than conventional file-encrypting ransomware deployment. The group has been identified among newer actors that rely on stolen-data exposure as the primary coercive mechanism, aligning it with the broader shift toward data-theft extortion in the ransomware ecosystem. Reported activity indicates large-scale data exfiltration and selective, sporadic targeting of higher-profile victims. Silent Team fits the contemporary financially motivated cybercrime model in which operators prioritize theft of sensitive information, public leak pressure, and reputational or regulatory harm over disruptive encryption. This operating style is consistent with extortion-only campaigns that emphasize exfiltration, post-compromise leverage, and leak-site style victim shaming. Available information directly supports data theft and extortion behavior, but does not provide high-confidence detail on the group’s tooling, intrusion chain, victimology by sector or geography, or any state affiliation. Silent Team is not supported as a nation-state actor and is best characterized as an emerging criminal extortion actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Silent Team is a ransomware group that, in 2025, adopted extortion-only tactics, focusing on data theft and public leaks rather than encrypting victim data.
Ransomware group known for large data exfiltration and sporadic high-profile attacks.
Newly emerged ransomware group (no specific victimology or TTPs detailed in the content).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.