Oct. 25, 2023, 12:35 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


  • Cisco Talos assesses with high confidence that YoroTrooper, an espionage-focused threat actor first active in June 2022, likely consists of individuals from Kazakhstan based on their use of Kazakh currency and fluency in Kazakh and Russian. The actor also appears to have a defensive interest in the website of the Kazakhstani state-owned email service and has rarely targeted Kazakh entities.

  • YoroTrooper attempts to obfuscate the origin of their operations, employing various tactics to make its malicious activity appear to emanate …

actor attacks azerbaijan cisco cisco talos currency defensive espionage high interest june kazakhstan origin russian state talos threat threat actor website yorotrooper

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States