YoroTrooper — APT Profile
YoroTrooper targets CIS country governments and energy sector organizations with custom RATs, and is attributed to Kazakhstan.Also tracked as
CIS-targeted actor, Silent Lynx, Cavalry Werewolf, ShadowSilk, Sturgeon Phisher, Comrade Saiga, Salted Earth, Sturgeon Fisher
Tools & malware
- AveMaria/Warzone RAT RAT
- Cobalt Strike Framework
- Custom Python RAT (Telegram C2) RAT
- FoalShell Backdoor
- Godzilla webshell Webshell
- Golang RAT implant RAT
- LAPLAS implant Backdoor
- LodaRAT RAT
- PowerShell RAT RAT
- ReverseSocks5Agent Tool
- Rust-based reverse shell implant Backdoor
- Silent Loader Loader
- SilentSweeper Backdoor
- StallionRAT RAT
- Stink Stealer Stealer
Vendor research
- Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan Cisco Talos
- Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency Cisco Talos
- ShadowSilk: A Cross-Border Binary Union for Data Exfiltration Group-IB
- Cavalry Werewolf raids Russia's public sector with trusted relationship attacks BI.ZONE
- Operation Peek-a-Baku: Silent Lynx APT makes sluggish shift to Dushanbe Seqrite
Countries linked to this actor
- Kazakhstan origin
- Tajikistan targets
- Uzbekistan targets