| Tool / Process | APAC to NALA targeting shift2 | Operation Silent Skimmer threat group card |
| Tool / Process | BadPotato2 | Operation Silent Skimmer threat group card |
| Tool / Process | Cobalt Strike2 | Operation Silent Skimmer threat group card |
| Tool / Process | CVE-2017-11317 unrestricted upload / weak encryption context7 | CVE-2017-11317 |
| Tool / Process | CVE-2019-18935 insecure deserialization / remote code execution context6 | CVE-2019-18935 |
| Tool / Process | Do not treat campaign name as a confirmed formal organization identity2 | Operation Silent Skimmer threat group card |
| Tool / Process | Financially motivated web-skimming campaign2 | Operation Silent Skimmer threat group card |
| Tool / Process | GodPotato2 | Operation Silent Skimmer threat group card |
| Tool / Process | Godzilla webshell2 | Operation Silent Skimmer threat group card |
| Tool / Process | JuicyPotato2 | Operation Silent Skimmer threat group card |
| Tool / Process | Living off the land2 | Operation Silent Skimmer threat group card |
| Tool / Process | Online payment business targeting2 | Operation Silent Skimmer threat group card |
| Tool / Process | Payment scraping from compromised websites2 | Operation Silent Skimmer threat group card |
| Tool / Process | Persistence after Telerik exploitation4 | Silent Skimmer gets loud again |
| Tool / Process | Point-of-sale provider targeting2 | Operation Silent Skimmer threat group card |
| Tool / Process | PowerShell RAT2 | Operation Silent Skimmer threat group card |
| Tool / Process | Python script usage in 2024 resurgence4 | Silent Skimmer gets loud again |
| Tool / Process | Reconnaissance commands after web-server compromise2 | Operation Silent Skimmer threat group card |
| Tool / Process | Sensitive payment-data extraction2 | Operation Silent Skimmer threat group card |
| Tool / Process | SharpToken2 | Operation Silent Skimmer threat group card |
| Tool / Process | SweetPotato2 | Operation Silent Skimmer threat group card |
| Tool / Process | Telerik UI exploitation for initial access4 | Silent Skimmer gets loud again |
| Tool / Process | Vulnerable web-server compromise2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1005 - Data from Local System2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1041 - Exfiltration Over C2 Channel2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1046 - Network Service Discovery2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1055 - Process Injection2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1059.001 - PowerShell2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1059.006 - Python4 | Silent Skimmer gets loud again |
| ATT&CK ID | T1068 - Exploitation for Privilege Escalation2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1078 - Valid Accounts2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1082 - System Information Discovery2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1083 - File and Directory Discovery2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1105 - Ingress Tool Transfer2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1119 - Automated Collection2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1190 - Exploit Public-Facing Application4 | Silent Skimmer gets loud again |
| ATT&CK ID | T1505.003 - Web Shell2 | Operation Silent Skimmer threat group card |
| ATT&CK ID | T1543.003 - Windows Service2 | Operation Silent Skimmer threat group card |
| CVE | CVE-2017-11317 - Telerik UI unrestricted file upload / weak encryption context7 | CVE-2017-11317 |
| CVE | CVE-2019-18935 - Telerik UI insecure deserialization / remote code execution context6 | CVE-2019-18935 |
| Alias / Related Name | BlackBerry naming: Silent Skimmer2 | Operation Silent Skimmer threat group card |
| Alias / Related Name | Operation Silent Skimmer1 | SOCRadar |
| Alias / Related Name | Silent Skimmer2 | Operation Silent Skimmer threat group card |
| Alias / Related Name | SOCRadar baseline: Operation Silent Skimmer1 | SOCRadar |
| Malware Family | RingQ loader5 | RingQ Loader malware leveraged in Silent Skimmer campaign |
| Campaign Context | 2022: ETDA/BlackBerry first-seen context for Silent Skimmer payment-scraping activity.2 | Operation Silent Skimmer threat group card |
| Campaign Context | 2024-05: Unit 42 investigated resurfaced Silent Skimmer activity exploiting Telerik UI vulnerabilities and dumping payment information.4 | Silent Skimmer gets loud again |
| Campaign Context | IntelliOS excludes raw payment-skimming scripts, victim payment data, webshell URLs, C2 infrastructure, and exploit instructions from the Operation Silent Skimmer card.1 | SOCRadar |
| CLASSIFICATION | ETDA/BlackBerry describe Silent Skimmer as a financially motivated campaign targeting online payment businesses and POS providers with payment scraping.2 | Operation Silent Skimmer threat group card |
| CLASSIFICATION | SOCRadar retains Operation Silent Skimmer as an APT Group card with China origin and Canada, Laos, and United States exposure context.1 | SOCRadar |
| COUNTRY | Canada1 | SOCRadar |
| COUNTRY | Lao People's Democratic Republic1 | SOCRadar |
| COUNTRY | United States2 | Operation Silent Skimmer threat group card |
| OBSERVABLE | Broadcom retained RingQ loader as malware leveraged in a Silent Skimmer campaign with Telerik exploitation context.5 | RingQ Loader malware leveraged in Silent Skimmer campaign |
| OBSERVABLE | ETDA preserves BlackBerry's description that Silent Skimmer compromises web servers and deploys payment-scraping mechanisms on websites to extract sensitive financial data.2 | Operation Silent Skimmer threat group card |
| OBSERVABLE | The Hacker News summarized Unit 42's Silent Skimmer resurgence and named CVE-2017-11317 and CVE-2019-18935 as exploited Telerik flaws.8 | Silent Skimmer / Telerik exploitation recap |
| OBSERVABLE | Unit 42 reported May 2024 incident response findings where attackers exploited Telerik UI vulnerabilities to access web servers and dump payment information.4 | Silent Skimmer gets loud again |
| REGION | Asia-Pacific2 | Operation Silent Skimmer threat group card |
| REGION | Latin America1 | SOCRadar |
| REGION | North America1 | SOCRadar |