Silent Lynx is a cyber-espionage threat actor active since at least late 2024 and publicly identified in 2025. It has been assessed as a likely Central Asian cluster, with reporting linking it to operations across Tajikistan, Kyrgyzstan, Uzbekistan, Turkmenistan, Azerbaijan, Russia, and China. The group has targeted government entities, diplomatic missions, government-affiliated think tanks, mining firms, transportation companies, communications organizations, and other politically or strategically relevant institutions. Campaigns have included targeting organizations involved in Azerbaijan-Russia diplomacy and entities connected to regional summits and intergovernmental negotiations. Some reporting has assessed the actor as likely Kazakhstan-based based on language fluency, regional focus, and operational context, but that attribution is not fully corroborated. Silent Lynx is associated with a cluster of overlapping aliases including YoroTrooper, Tomiris, Cavalry Werewolf, Comrade Saiga, ShadowSilk, SturgeonPhisher, and ShadowSilk. Reporting indicates at least partial overlap with YoroTrooper and SturgeonPhisher, while equivalence with all aliases is not uniformly confirmed across vendors. It is one of several threat groups first newly tracked by some researchers in 2025. The actor primarily relies on spearphishing for initial access, especially attachment-based lures themed around diplomatic, political, and strategic-cooperation subjects. Observed delivery chains have used archive files containing shortcut files that launch obfuscated PowerShell, followed by retrieval of additional payloads from public code-hosting services. Silent Lynx has used GitHub as a dead-drop or staging mechanism, web protocols over HTTPS for command and control, and exfiltration over established C2 channels. The group has also been reported using cloud and social platforms such as Telegram and Discord as command-and-control infrastructure in related activity. Malware and tooling associated with Silent Lynx include Silent Loader, SilentSweeper, LAPLAS Implant, and in at least one campaign the open-source Ligolo-ng reverse shell. Tradecraft includes PowerShell-based execution, obfuscated .NET payloads, base64-encoded commands, staged payload delivery, and selective use of multiple implants. Techniques consistently associated with the actor include spearphishing attachment delivery, PowerShell execution, obfuscation, use of web protocols for C2, and data exfiltration over the C2 channel. Operationally, Silent Lynx has been characterized as comparatively hasty and prone to OPSEC mistakes. Reported weaknesses include poor Russian grammar in lures, infrastructure reuse, and predictable staging patterns. Despite these shortcomings, the actor has demonstrated sustained interest in diplomatic and geopolitical intelligence collection, as well as strategic-sector targeting such as mining and transport, indicating a focused espionage mission aligned with regional political and economic priorities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly disclosed pro-government APT group active against organizations in Russia and the CIS in 2025.
Cyber espionage cluster targeting diplomats, government think tanks, and sectors including mining, transport, and communications using spear-phishing archives with LNK files, base64-obfuscated PowerShell, GitHub dead-drop staging, and implants such as SilentSweeper over HTTPS C2.
Targeting Russia's mining sector; researchers assess the group is likely Kazakhstan-based.
Multi-stage intrusion activity targeting government/think-tank and banking-related entities in Kyrgyzstan and Turkmenistan, using loaders written in PowerShell, Golang, and C++.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.