SILENT LYNX
YOROTROOPER (POSSIBLE OVERLAP)
Threat IntelligenceAPTJanuary 23, 202615 min read

Silent Lynx APT: Threat Intelligence Profile

Central Asian APT targeting government entities and embassies in the region with PowerShell-based implants and Telegram bot infrastructure for C2.

Scroll

Silent Lynx APT (also known as Silent Lynx, YoroTrooper (possible overlap)) is a state-sponsored advanced persistent threat group attributed to Central Asia (Kazakhstan suspected), active since 2022. The group primarily targets Central Asian governments, embassies, energy sectors.

Overview & Attribution

Central Asian APT targeting government entities and embassies in the region with PowerShell-based implants and Telegram bot infrastructure for C2.

Threat Assessment

Silent Lynx APT has been active since 2022, attributed to Central Asia (Kazakhstan suspected). The group is known for targeting Central Asian governments, embassies, energy using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

Silent Lynx APT employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on Central Asian governments, embassies, energy sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

Silent Lynx APT is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentThemed spearphishing
ExecutionT1059.001 PowerShellPowerShell-based payloads
PersistenceT1053.005 Scheduled TaskTask persistence
Defense EvasionT1027 Obfuscated FilesScript obfuscation
C2T1102 Web ServiceTelegram bot C2
ExfiltrationT1567 Exfiltration Over Web ServiceTelegram exfiltration

Notable Campaigns

Silent Lynx APT has been linked to multiple significant campaigns targeting Central Asian governments, embassies, energy organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against Silent Lynx APT

Mjolnir Security provides specialized capabilities to detect and respond to Silent Lynx APT operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for Silent Lynx APT TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of Silent Lynx APT campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: January 23, 2026