SILENTLOOP
SILENTLOOP is a PowerShell-based malware script used in a CERT-UA-reported campaign attributed to threat cluster UAC-0247 targeting Ukrainian local governments, municipal authorities, clinical hospitals, emergency medical services, and in some cases representatives of Ukraine’s Defense Forces and FPV drone operators. It is used as a persistence component alongside AGINGFLY. High-confidence reporting states that SILENTLOOP can execute commands on infected systems, automatically update its configuration, and retrieve the current or latest command-and-control server IP address from a Telegram channel, with fallback mechanisms for determining the C2 address. The broader intrusion activity used phishing emails themed around humanitarian aid, malicious archives, LNK and HTA execution chains, and in some cases trojanized software delivery via Signal. Within these operations, SILENTLOOP supported maintaining attacker access and C2 resiliency by dynamically obtaining updated server information from Telegram.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Another tool, SilentLoop, can execute commands and retrieve the current address of the attackers’ command-and-control server via a Telegram channel.
Techniques & procedures
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
3 techniques
Execution
For persistence, the attackers deployed the malware AGINGFLY alongside a PowerShell script, SILENTLOOP, which manages commands, updates configuration, and retrieves C2 server data via Telegram with backup mechanisms.
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Discovery
1 technique
Discovery
Command and Control
4 techniques
Command and Control
Another tool, SilentLoop, can execute commands and retrieve the current address of the attackers’ command-and-control server via a Telegram channel.
Комунікація із сервером управління здійснюється за допомогою вебсокетів...
IOCs tracked for this family
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PowerShell persistence script that runs commands, updates configuration, and retrieves current C2 IP addresses from a Telegram channel, with backup mechanisms if the primary source fails.
A PowerShell-based malware component used to manage commands, update configuration, and retrieve C2 server data via Telegram with fallback mechanisms.
A PowerShell-based backdoor/script with command execution, configuration update, and resilient C2 discovery via Telegram and fallback mechanisms.
A PowerShell-based malware component used to execute commands, update configuration, and retrieve C2 server addresses from Telegram or fallback mechanisms.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.