The Silent Lynx advanced persistent threat (APT) group has conducted targeted espionage campaigns against Central Asian diplomatic entities, leveraging malicious LNK files to deploy reverse shells via GitHub and custom implants. Security researchers identified multiple attack waves, including the use of spear-phishing emails with fake RAR archives and the deployment of a variety of malware such as the SILENT LOADER, LAPLAS implant, and SilentSweeper. The campaigns focused on exploiting relationships between Azerbaijan and Russia, as well as targeting China-Central Asian entities, with the primary objective of intelligence gathering.
Technical analysis revealed that Silent Lynx utilized both custom-made and open-source offensive tools, adapting their infection chains over time and occasionally making operational security mistakes that aided attribution. The group is known for posing as government officials and targeting think tanks and government employees, with infrastructure and tactics mapped to MITRE ATT&CK techniques. Indicators of compromise and early remediation steps have been published to assist defenders in mitigating these threats.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting revealed technical details of the campaign's attack chain, including exploitation of LNK file weaknesses to deploy reverse shells and use GitHub as part of the delivery or command infrastructure. This disclosure provided new insight into the tactics and tooling used by Silent Lynx in the operation.
Seqrite and Security Online report an espionage campaign dubbed Operation Peek-a-Baku in which the Silent Lynx APT targeted diplomatic or government-related entities in Dushanbe, Tajikistan. The operation focused on Central Asian diplomatic interests and used malware delivery through malicious shortcut files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.