Also known as: Salted Earth, Sturgeon Fisher, ShadowSilk, Silent Lynx, Cavalry Werewolf, SturgeonPhisher, Comrade Saiga
YoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on Cisco Talos analysis. YoroTrooper was also observed compromising accounts from at least two international organizations: a critical European Union health care agency and the World Intellectual Property Organization. Successful compromises also included Embassies of European countries including Azerbaijan and Turkmenistan.
Executive Summary
YoroTrooper is a threat actor targeting government and energy sectors in Commonwealth of Independent States (CIS) countries such as Azerbaijan and Tajikistan, with additional focus on international organizations including EU health care agencies and World Intellectual Property Organization. Their operations involve sophisticated phishing techniques and account compromise, posing significant risks to critical infrastructure and global institutions.
Goals & Targeting
YoroTrooper targets government and energy sectors likely to gather sensitive information for espionage purposes or to disrupt national infrastructure as part of a larger strategic objective. Their targeting of international organizations may aim to influence global policies or gain competitive advantages in intellectual property. The actor's focus on embassies suggests an interest in diplomatic intelligence, possibly to support state-sponsored activities.
Enhanced Description
YoroTrooper has demonstrated a strategic approach in targeting high-value sectors such as government and energy within CIS member states. Their campaigns have extended to compromising accounts within international organizations, including European Union health care agencies and the World Intellectual Property Organization, indicating a potential interest in data theft or espionage. The actor's operations have also included breaching embassies of European countries like Azerbaijan and Turkmenistan, suggesting a broader geopolitical agenda.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
YoroTrooper's campaigns have shown persistence over several years, indicating a well-organized and possibly state-sponsored group. Their operations often involve multiple countries, suggesting a long-term strategy to infiltrate various sectors. Notable activities include compromising critical infrastructure and international organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high regarding YoroTrooper's targeting patterns and victims, based on Cisco Talos analysis. However, specific details about their TTPs and tools remain unclear, leaving gaps in understanding their full capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics