YoroTrooper is a cyber threat actor targeting government, energy, and embassy entities primarily across CIS countries.
Analyst brief
YoroTrooper, known by multiple aliases, is a cyber threat actor primarily targeting government and energy organizations in CIS countries like Azerbaijan, Tajikistan, and Kyrgyzstan. They have also successfully compromised European embassies in Azerbaijan and Turkmenistan. While specific TTPs and tools are not detailed in the provided description, defenders should focus on monitoring for targeted spear-phishing and credential theft campaigns aimed at government entities, diplomatic missions, and critical infrastructure.
YoroTrooper
Salted EarthSturgeon FisherShadowSilk
unknown
YoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on Cisco Talos analysis. YoroTrooper was also observed compromising accounts from at least two international organizations: a critical European Union health care agency and the World Intellectual Property Organization. Successful compromises also included Embassies of European countries including Azerbaijan and Turkmenistan.
Which countries' organizations does YoroTrooper primarily target?+
Based on analysis, YoroTrooper primarily targets government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other CIS countries.
What kind of international entities has YoroTrooper successfully compromised?+
YoroTrooper has successfully compromised accounts from international organizations such as a critical European Union health care agency and the World Intellectual Property Organization, as well as European embassies in Azerbaijan and Turkmenistan.