YoroTrooper is a cyber espionage group that first emerged in June 2022, primarily targeting government and energy sector entities across Eastern Europe and Central Asia. The group is assessed with high confidence to originate from Kazakhstan, although it actively attempts to obfuscate its true origin by making operations appear to emanate from Azerbaijan. YoroTrooper's core motivation is espionage and intelligence gathering, potentially aligned with Kazakh state interests or for financial gain through selling restricted state information. A defining characteristic of the group is its continuous evolution, frequently retooling its malware and adapting tactics, techniques, and procedures (TTPs) in response to public disclosures, including porting Python-based implants to PowerShell. This group operates under various aliases, such as Silent Lynx, Cavalry Werewolf, SturgeonPhisher, ShadowSilk, and Comrade Saiga.