Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors YoroTrooper

Also known as: Salted Earth, Sturgeon Fisher, ShadowSilk, Silent Lynx, Cavalry Werewolf, SturgeonPhisher, Comrade Saiga

Description

YoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on Cisco Talos analysis. YoroTrooper was also observed compromising accounts from at least two international organizations: a critical European Union health care agency and the World Intellectual Property Organization. Successful compromises also included Embassies of European countries including Azerbaijan and Turkmenistan.

AI Analysis

· 1 week ago

Executive Summary

YoroTrooper is a threat actor targeting government and energy sectors in Commonwealth of Independent States (CIS) countries such as Azerbaijan and Tajikistan, with additional focus on international organizations including EU health care agencies and World Intellectual Property Organization. Their operations involve sophisticated phishing techniques and account compromise, posing significant risks to critical infrastructure and global institutions.

Goals & Targeting

YoroTrooper targets government and energy sectors likely to gather sensitive information for espionage purposes or to disrupt national infrastructure as part of a larger strategic objective. Their targeting of international organizations may aim to influence global policies or gain competitive advantages in intellectual property. The actor's focus on embassies suggests an interest in diplomatic intelligence, possibly to support state-sponsored activities.

Enhanced Description

YoroTrooper has demonstrated a strategic approach in targeting high-value sectors such as government and energy within CIS member states. Their campaigns have extended to compromising accounts within international organizations, including European Union health care agencies and the World Intellectual Property Organization, indicating a potential interest in data theft or espionage. The actor's operations have also included breaching embassies of European countries like Azerbaijan and Turkmenistan, suggesting a broader geopolitical agenda.

Key Capabilities

  • Spear-phishing
  • Account compromise
  • Social engineering
  • Data exfiltration

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Lateral Movement

ATT&CK Techniques

T1059
T1059.003
T1566.003

Software / Tooling

Spear-phishing emails with malicious attachments
Credential harvesting tools
Custom malware for persistence

Campaigns & Victims

YoroTrooper's campaigns have shown persistence over several years, indicating a well-organized and possibly state-sponsored group. Their operations often involve multiple countries, suggesting a long-term strategy to infiltrate various sectors. Notable activities include compromising critical infrastructure and international organizations.

IOC Patterns

  • Spear-phishing emails with .doc or .exe attachments
  • Malicious scripts executing via WMI commands for persistence

Recommended Actions

  • Deploy advanced email filtering solutions
  • Implement multi-factor authentication for critical accounts
  • Conduct regular network monitoring for异常 traffic and data exfiltration attempts

Suggested Tags

APT
espionage
energy-sector
government-targeting

Confidence Assessment

Confidence is high regarding YoroTrooper's targeting patterns and victims, based on Cisco Talos analysis. However, specific details about their TTPs and tools remain unclear, leaving gaps in understanding their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
APT
espionage
energy-sector
government-targeting

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.