Uptime Hamster: 11d 2h 27mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza YoroTrooper

YoroTrooper

0 incidentes 0 paises 0 sectores apt KZ Ultimo: -
Aliases: Cavalry Werewolf, Comrade Saiga, Salted Earth, ShadowSilk, Silent Lynx, Sturgeon Fisher, SturgeonPhisher
Ver en IntelTracker → APTTrail →
YoroTrooper is a cyber espionage group that first emerged in June 2022, primarily targeting government and energy sector entities across Eastern Europe and Central Asia. The group is assessed with high confidence to originate from Kazakhstan, although it actively attempts to obfuscate its true origin by making operations appear to emanate from Azerbaijan. YoroTrooper's core motivation is espionage and intelligence gathering, potentially aligned with Kazakh state interests or for financial gain through selling restricted state information. A defining characteristic of the group is its continuous evolution, frequently retooling its malware and adapting tactics, techniques, and procedures (TTPs) in response to public disclosures, including porting Python-based implants to PowerShell. This group operates under various aliases, such as Silent Lynx, Cavalry Werewolf, SturgeonPhisher, ShadowSilk, and Comrade Saiga.

Aliases del actor

Cavalry WerewolfComrade SaigaSalted EarthShadowSilkSilent LynxSturgeon FisherSturgeonPhisher

Actores similares

lynxransomware · 414silentransomgroupactor · 36silentransomware · 2SilentRansomGroupactor · 2apt-earthberberokaactor · 1apt-earthhundunactor · 1apt-earthwendigoactor · 1apt-finfisheractor · 1rare-werewolfactor · 1earthkapreactor · 1
Motivacion