logo

Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations

ID: 6a2b720e-1e74-5df8-9e91-78f8dc13e6c0

STIX ID: report--6a2b720e-1e74-5df8-9e91-78f8dc13e6c0

Feed Name: Seqrite Blog

Threat Score
85/100

Date Published: 2025-01-21

Date Updated: 2026-04-30

Author: Subhajeet Singha

...
...

Seqrite Labs reports two coordinated phishing campaigns attributed to a group named Silent Lynx targeting Kyrgyzstan government entities (National Bank and Ministry of Finance). The attacks use RAR/ISO lures delivering a C++ loader that runs a Base64-encoded PowerShell implant (which uses a Telegram bot for command & control and data exfiltration) and a separate Golang reverse-shell implant; the report includes technical analysis, IOCs (hashes, domains, Telegram bot tokens), infrastructure findings, and a medium-confidence attribution linking Silent Lynx to the Kazakhstan-aligned YoroTrooper group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.