ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram Bots

A new wave of attacks against Central Asian and Asia-Pacific (APAC) government entities has been linked to a threat activity cluster called ShadowSilk.

Group-IB reports that about three dozen victims have been found, with the majority of the intrusions being intended to exfiltrate data. The hacker group’s infrastructure and toolkit are similar to those used by threat actors known as YoroTrooper, SturgeonPhisher, and Silent Lynx.

Campaign victims in Uzbekistan, Kyrgyzstan, Myanmar, Tajikistan, Pakistan, and Turkmenistan are mostly government agencies, with smaller numbers of victims coming from the energy, manufacturing, retail, and transportation industries.

According to researchers Nikita Rostovcev and Sergei Turner, the operation is conducted by a multilingual crew, with Chinese-speaking operators leading intrusions and Russian-speaking developers linked to legacy YoroTrooper code read more about ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram Bots.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *