SYMBOLCOMMON_NAMEaka. SYNONYMS

YoroTrooper  (Back to overview)

aka: Cavalry Werewolf, Comrade Saiga, Salted Earth, ShadowSilk, Silent Lynx, Sturgeon Fisher, SturgeonPhisher

YoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on Cisco Talos analysis. YoroTrooper was also observed compromising accounts from at least two international organizations: a critical European Union health care agency and the World Intellectual Property Organization. Successful compromises also included Embassies of European countries including Azerbaijan and Turkmenistan.


Associated Families
ps1.unidentified_005 win.foalshell win.stallion_rat

References
2025-11-03SeqriteSathwik Ram Prakki, Subhajeet Singha
Operation Peek-a-Baku: Silent Lynx APT makes sluggish shift to Dushanbe
Laplas (Reverseshell) SilentSweeper YoroTrooper
2025-10-02Medium BI.ZONEBI.ZONE
Cavalry Werewolf raids Russia’s public sector with trusted relationship attacks
FoalShell StallionRAT YoroTrooper
2025-08-27Group-IBNikita Rostovcev, Sergei Turner
ShadowSilk: A Cross-Border Binary Union for Data Exfiltration
Cobalt Strike YoroTrooper
2025-01-21SeqriteSathwik Ram Prakki, Subhajeet Singha
Silent Lynx APT Targets Various Entities Across Kyrgyzstan & Neighbouring Nations
Unidentified PS 005 (Telegram Bot) YoroTrooper
2023-10-25Cisco TalosAsheer Malhotra, Vitor Ventura
Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan
Ave Maria Loda YoroTrooper
2023-03-14Cisco TalosAsheer Malhotra, Vitor Ventura
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency
Poet RAT Loda Kasablanka YoroTrooper

Credits: MISP Project