Silent Lynx is a cyber-espionage threat actor first publicly tracked in 2025 and assessed to have been active since at least late 2024. The group has been linked to operations against government entities, diplomatic missions, government-affiliated think tanks, mining firms, transportation companies, and communications organizations. Reported aliases and overlapping tracking names include YoroTrooper, Tomiris, Cavalry Werewolf, Comrade Saiga, ShadowSilk, and SturgeonPhisher, although full overlap across all labels is not uniformly confirmed. Available reporting assesses the actor as likely Kazakhstan-based. The group’s targeting is concentrated in Central Asia and adjacent geopolitical corridors, including Tajikistan, Kyrgyzstan, Uzbekistan, Azerbaijan, Russia, China, and entities involved in Azerbaijan-Russia diplomacy. Its operations are characterized by politically themed spearphishing that impersonates government bodies and uses lures tied to summits, strategic cooperation, and intergovernmental negotiations. Initial access commonly relies on malicious attachments, including archive files containing shortcut-based execution chains that launch obfuscated PowerShell. Silent Lynx has used GitHub as a staging or dead-drop mechanism and has deployed multiple implants and tooling families, including Silent Loader, LAPLAS Implant, SilentSweeper, and in at least one campaign the open-source Ligolo-ng reverse shell. Command and control has been conducted over web protocols, including HTTPS, with data exfiltration occurring over the C2 channel. Reported tradecraft includes PowerShell execution, obfuscated .NET payloads, and infrastructure reuse. The actor has also been noted for operational-security weaknesses such as poor Russian grammar in lures, predictable staging patterns, and hasty execution practices. The actor’s victimology and lure themes indicate a primary focus on intelligence collection rather than disruption or monetization. Silent Lynx is one of several newly disclosed APT clusters identified in 2025 and is notable for sustained espionage activity against diplomatic, governmental, and strategically important commercial targets in the CIS and broader Central Asian region.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly disclosed pro-government APT group active against organizations in Russia and the CIS in 2025.
Cyber espionage cluster targeting diplomats, government think tanks, and sectors including mining, transport, and communications using spear-phishing archives with LNK files, base64-obfuscated PowerShell, GitHub dead-drop staging, and implants such as SilentSweeper over HTTPS C2.
Targeting Russia's mining sector; researchers assess the group is likely Kazakhstan-based.
Multi-stage intrusion activity targeting government/think-tank and banking-related entities in Kyrgyzstan and Turkmenistan, using loaders written in PowerShell, Golang, and C++.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.