logo

ShadowSilk: A Cross-Border Binary Union for Data Exfiltration

ID: 4921474f-489c-5fd0-8f2e-e53f04736a26

STIX ID: report--4921474f-489c-5fd0-8f2e-e53f04736a26

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2025-08-27

Date Updated: 2026-04-28

...
...

ShadowSilk is an active APT cluster (since at least 2023, active as of July 2025) targeting government organizations across Central Asia and the broader APAC region for data exfiltration. Group-IB links ShadowSilk to YoroTrooper tooling and infrastructure, identifies Chinese- and Russian-speaking subgroups, and documents a diverse toolkit (Telegram-based C2, PowerShell loaders, Cobalt Strike/Metasploit, webshells, purchased RAT/web panels) along with IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.