YoroTrooper
Also reported as Silent Lynx, Salted Earth, Sturgeon Fisher, ShadowSilk, Cavalry Werewolf and 2 other names. Linked to Kazakhstan by three sources.
Reports per quarter
Techniques seen in the last two years
- T1059.001 3 reports
- T1204.002 3 reports
- T1036 2 reports
- T1041 2 reports
- T1071 2 reports
- T1204.001 2 reports
- T1566.001 2 reports
- T1007 1 report
- T1012 1 report
- T1016 1 report
Show all 46 techniques Show fewer
- T1018 1 report
- T1027 1 report
- T1027.002 1 report
- T1027.010 1 report
- T1046 1 report
- T1053.005 1 report
- T1055.002 1 report
- T1056.001 1 report
- T1059.003 1 report
- T1078.002 1 report
- T1083 1 report
- T1087 1 report
- T1095 1 report
- T1106 1 report
- T1485 1 report
- T1489 1 report
- T1491 1 report
- T1546.015 1 report
- T1547.001 1 report
- T1552.001 1 report
- T1560.001 1 report
- T1566.002 1 report
- T1567.002 1 report
- T1574.001 1 report
- T1583.001 1 report
- T1583.003 1 report
- T1583.004 1 report
- T1584.001 1 report
- T1589.002 1 report
- T1590 1 report
- T1590.005 1 report
- T1591 1 report
- T1591.002 1 report
- T1595 1 report
- T1608.001 1 report
- T1657 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2013-4786
- CVE-2018-0171 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2020-12641 KEV
- CVE-2020-35730 KEV
- CVE-2021-34527 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-37042 KEV ransomware
Show all 29 CVEs Show fewer
- CVE-2022-41091 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20273 KEV
- CVE-2023-23397 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-21413 KEV
- CVE-2024-27956
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ave Maria (Malware Family)
Show all 15 reports Show fewer
-
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency
Newest first. Details opens the report in Explore.