ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram Bots
A new wave of attacks against Central Asian and Asia-Pacific (APAC) government entities has been linked to a threat activity cluster called ShadowSilk.
Group-IB reports that about three dozen victims have been found, with the majority of the intrusions being intended to exfiltrate data. The hacker group's infrastructure and toolkit are similar to those used by threat actors known as YoroTrooper, SturgeonPhisher, and Silent Lynx.
Campaign victims in Uzbekistan, Kyrgyzstan, Myanmar, Tajikistan, Pakistan, and Turkmenistan are mostly government agencies, with smaller numbers of victims coming from the energy, manufacturing, retail, and transportation industries.
According to researchers Nikita Rostovcev and Sergei Turner, the operation is conducted by a multilingual crew, with Chines...

