{"id":8196,"date":"2025-11-05T10:03:28","date_gmt":"2025-11-05T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/05\/silent-lynx-apt-new-attack-targeting-governmental-employees-posing-as-officials\/"},"modified":"2025-11-05T10:03:28","modified_gmt":"2025-11-05T10:03:28","slug":"silent-lynx-apt-new-attack-targeting-governmental-employees-posing-as-officials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/05\/silent-lynx-apt-new-attack-targeting-governmental-employees-posing-as-officials\/","title":{"rendered":"Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials"},"content":{"rendered":"<p>    Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Silent Lynx, a sophisticated threat group that has been tracked since 2024, continues its relentless espionage campaign against government entities across Central Asia.<\/p>\n<p>Seqrite analysts identified the group as the first to assign this nomenclature, distinguishing it from multiple overlapping aliases including YoroTrooper, Sturgeon Phisher, and ShadowSilk.<\/p>\n<p>The group has become notorious for orchestrating spear-phishing campaigns while impersonating government officials, specifically targeting governmental employees with malicious attachments designed to harvest sensitive information.<\/p>\n<p>The threat group primarily leverages fabricated summit-related communications to distribute its weaponized payload.<\/p>\n<p>Seqrite researchers noted that Silent Lynx demonstrates a pattern of hastily constructed <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a> targeting diplomatic entities involved in high-level international meetings.<\/p>\n<p>The group\u2019s operations extend across multiple Central Asian nations including Tajikistan, Azerbaijan, Russia, and China, with strategic focus on nations involved in cross-border infrastructure projects and diplomatic initiatives.<\/p>\n<p>Seqrite analysts <a href=\"https:\/\/www.seqrite.com\/blog\/operation-peek-a-baku-silent-lynx-apt-dushanbe-espionage\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> two distinct campaigns in 2025, both employing similar attack methodologies but targeting different geopolitical relationships.<\/p>\n<p>The first campaign, discovered in October 2025, targeted diplomatic entities involved in Russia-Azerbaijan summit preparations, while the second focused on entities associated with China-Central Asian relations.<\/p>\n<p>The timing and thematic consistency of these campaigns reveal a coordinated espionage operation driven by geopolitical interests rather than financial gain.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-technical-arsenal\"><strong>Infection Mechanism and Technical Arsenal<\/strong><\/h2>\n<p>The infection chain begins with a deceptive RAR archive bearing benign filenames like \u201c\u041f\u043b\u0430\u043d \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0435 \u0441\u0442\u0440\u0430\u0442\u0435\u0433\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u0447\u0435\u0441\u0442\u0432\u0430.pdf.rar\u201d (Plan for Development of Strategic Cooperation).<\/p>\n<p>When extracted, the archive reveals a malicious Windows shortcut file that abuses PowerShell.exe to download and execute obfuscated scripts from <a href=\"https:\/\/cybersecuritynews.com\/23000-github-repositories-targeted\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub repositories<\/a>.<\/p>\n<p>The LNK file contains working directory metadata pointing to C:UsersGoBusOneDrive\u0420\u0430\u0431\u043e\u0447\u0438\u0439 \u0441\u0442\u043e\u043b, serving as a pivot point for tracking additional campaigns.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiGCWxCCk8joLBWVwZccFmNq9RAl0yDp0B4V2eL9hHAH7_EJqrFcqj2okz9YR5_KmOQmi6SixXQCnUbRv28qQAKjWtI_t5f1ZnV-UicsjHDmhiARwpLeAAqnZD_5uPdSQFdIncjj6y1iRPA69tv_IWl8QPDngXrEYa7YdO3Xum7wgFDoHOn7qcnUuQiAD8\/s16000\/Infection%2520Chain%2520%28Source%2520-%2520Seqrite%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Infection Chain (Source \u2013 Seqrite)<\/figcaption><\/figure>\n<\/div>\n<p>The downloaded PowerShell script contains Base64-encoded reverse shell code that connects to remote command-and-control servers on port 443.<\/p>\n<p>The decoded payload establishes a persistent TCP connection where it reads commands from operators, executes them via Invoke-Expression, and returns output across the same channel.<\/p>\n<p>Seqrite researchers identified three primary implants deployed in these campaigns: Silent Loader (a C++ based downloader), Laplas (a TCP and TLS-based reverse shell), and SilentSweeper (a .NET implant capable of extracting and executing embedded PowerShell scripts).<\/p>\n<p>The SilentSweeper implant accepts multiple arguments including -extract for writing embedded malicious <a href=\"https:\/\/cybersecuritynews.com\/new-yurei-ransomware-with-powershell-commands\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> to disk and -debug for troubleshooting.<\/p>\n<p>It reads a file named qw.ps1 from its Resources section, executes the contents, and downloads additional reverse shell payloads.<\/p>\n<p>Beyond remote access, Seqrite analysts observed deployment of Ligolo-ng, an open-source tunneling tool, providing operators unrestricted command execution capabilities on compromised systems.<\/p>\n<p>The multi-stage infection mechanism demonstrates sophisticated operational security awareness despite numerous OPSEC blunders that facilitated attribution and tracking.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/silent-lynx-apt-new-attack\/\">Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/silent-lynx-apt-new-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials Silent Lynx, a sophisticated threat group that has been tracked since 2024, continues its relentless espionage campaign against government entities across Central Asia. Seqrite analysts identified the group as the first to assign this nomenclature, distinguishing it from multiple overlapping aliases including YoroTrooper, Sturgeon [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8196","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8196"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8196"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8196\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}