Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations
ID: 6a2b720e-1e74-5df8-9e91-78f8dc13e6c0
STIX ID: report--6a2b720e-1e74-5df8-9e91-78f8dc13e6c0
Feed Name: Seqrite Blog
Seqrite Labs reports two coordinated phishing campaigns attributed to a group named Silent Lynx targeting Kyrgyzstan government entities (National Bank and Ministry of Finance). The attacks use RAR/ISO lures delivering a C++ loader that runs a Base64-encoded PowerShell implant (which uses a Telegram bot for command & control and data exfiltration) and a separate Golang reverse-shell implant; the report includes technical analysis, IOCs (hashes, domains, Telegram bot tokens), infrastructure findings, and a medium-confidence attribution linking Silent Lynx to the Kazakhstan-aligned YoroTrooper group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
