Cyber Security News

Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials

Silent Lynx, a sophisticated threat group that has been tracked since 2024, continues its relentless espionage campaign against government entities across Central Asia.

Seqrite analysts identified the group as the first to assign this nomenclature, distinguishing it from multiple overlapping aliases including YoroTrooper, Sturgeon Phisher, and ShadowSilk.

The group has become notorious for orchestrating spear-phishing campaigns while impersonating government officials, specifically targeting governmental employees with malicious attachments designed to harvest sensitive information.

The threat group primarily leverages fabricated summit-related communications to distribute its weaponized payload.

Seqrite researchers noted that Silent Lynx demonstrates a pattern of hastily constructed campaigns targeting diplomatic entities involved in high-level international meetings.

The group’s operations extend across multiple Central Asian nations including Tajikistan, Azerbaijan, Russia, and China, with strategic focus on nations involved in cross-border infrastructure projects and diplomatic initiatives.

Seqrite analysts identified two distinct campaigns in 2025, both employing similar attack methodologies but targeting different geopolitical relationships.

The first campaign, discovered in October 2025, targeted diplomatic entities involved in Russia-Azerbaijan summit preparations, while the second focused on entities associated with China-Central Asian relations.

The timing and thematic consistency of these campaigns reveal a coordinated espionage operation driven by geopolitical interests rather than financial gain.

Infection Mechanism and Technical Arsenal

The infection chain begins with a deceptive RAR archive bearing benign filenames like “План развитие стратегического сотрудничества.pdf.rar” (Plan for Development of Strategic Cooperation).

When extracted, the archive reveals a malicious Windows shortcut file that abuses PowerShell.exe to download and execute obfuscated scripts from GitHub repositories.

The LNK file contains working directory metadata pointing to C:\Users\GoBus\OneDrive\Рабочий стол, serving as a pivot point for tracking additional campaigns.

Infection Chain (Source – Seqrite)

The downloaded PowerShell script contains Base64-encoded reverse shell code that connects to remote command-and-control servers on port 443.

The decoded payload establishes a persistent TCP connection where it reads commands from operators, executes them via Invoke-Expression, and returns output across the same channel.

Seqrite researchers identified three primary implants deployed in these campaigns: Silent Loader (a C++ based downloader), Laplas (a TCP and TLS-based reverse shell), and SilentSweeper (a .NET implant capable of extracting and executing embedded PowerShell scripts).

The SilentSweeper implant accepts multiple arguments including -extract for writing embedded malicious PowerShell to disk and -debug for troubleshooting.

It reads a file named qw.ps1 from its Resources section, executes the contents, and downloads additional reverse shell payloads.

Beyond remote access, Seqrite analysts observed deployment of Ligolo-ng, an open-source tunneling tool, providing operators unrestricted command execution capabilities on compromised systems.

The multi-stage infection mechanism demonstrates sophisticated operational security awareness despite numerous OPSEC blunders that facilitated attribution and tracking.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

22 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

58 minutes ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

1 hour ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

2 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

3 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

5 hours ago