{
  "name": "Operation Peek-a-Baku: Silent Lynx APT Targets Dushanbe with Espionage Campaign",
  "slug": "operation-peek-a-baku-silent-lynx-apt-targets-dushanbe-with-espionage-campaign",
  "description": "The Silent Lynx APT group has been conducting espionage campaigns targeting Central Asian nations, Russia, China, and Azerbaijan. Two main campaigns were identified: one focusing on Russia-Azerbaijan relations and another on China-Central Asia relations. The group uses various malware including PowerShell scripts, .NET implants, and C++ reverse shells. They leverage spear-phishing with malicious attachments, GitHub-hosted payloads, and scheduled tasks for persistence. The campaigns aim to gather intelligence on diplomatic communications, transportation projects, and other strategic initiatives. Silent Lynx shows a pattern of targeting summit meetings and infrastructure deals in the region, with a particular focus on events in Dushanbe, Tajikistan.",
  "published": "2025-11-05T11:36:24+00:00",
  "created_at": "2025-11-05T11:36:24+00:00",
  "modified_at": "2025-11-05T20:49:05+00:00",
  "created_at_opencti": "2025-11-05T11:36:24+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    ".net",
    "2025-11-05",
    "apt",
    "azerbaijan",
    "central asia",
    "china",
    "espionage",
    "laplas",
    "ligolo-ng",
    "powershell",
    "reverse shell",
    "russia",
    "silent loader",
    "silentsweeper"
  ],
  "related_entities": {
    "intrusion_sets": [
      {
        "id": "61704dc6-b595-44e1-a2df-602af9b423ce",
        "name": "Silent Lynx",
        "slug": "silent-lynx"
      }
    ],
    "attack_patterns": [
      {
        "id": "16e4fc82-7c0b-4d1a-b784-b804b4df26dc",
        "name": "T1204.001"
      },
      {
        "id": "32b33067-6566-4b8d-be80-e96f765d84de",
        "name": "T1059.001"
      },
      {
        "id": "88fa397b-4cc9-42c0-b52d-4108f9630529",
        "name": "T1095"
      },
      {
        "id": "196f2a64-c55b-47a6-8e38-beb76ba700b6",
        "name": "T1204.002"
      },
      {
        "id": "60972cf6-e90b-4600-af3c-13c468391d9c",
        "name": "T1106"
      },
      {
        "id": "dc410646-9cdd-427b-92e7-179a54f78f90",
        "name": "T1566.001"
      },
      {
        "id": "dc342445-1b78-48b4-aa06-89ed2ad7c28e",
        "name": "T1071"
      },
      {
        "id": "7d7ac733-6442-416f-8669-c302dd0843b9",
        "name": "T1036"
      },
      {
        "id": "0c836307-129e-4ff7-a532-180c633cacba",
        "name": "T1027"
      },
      {
        "id": "fa3b8b48-d97c-4242-83a6-07d435a5a79e",
        "name": "T1041"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "Turkmenistan"
      },
      {
        "id": "",
        "name": "Kyrgyzstan"
      },
      {
        "id": "",
        "name": "Tajikistan"
      },
      {
        "id": "",
        "name": "Azerbaijan"
      },
      {
        "id": "",
        "name": "Uzbekistan"
      },
      {
        "id": "",
        "name": "China"
      },
      {
        "id": "",
        "name": "Russian Federation"
      },
      {
        "id": "",
        "name": "Mining"
      },
      {
        "id": "",
        "name": "Transportation"
      },
      {
        "id": "",
        "name": "Telecommunications"
      },
      {
        "id": "",
        "name": "Government"
      }
    ]
  },
  "external_refs": [
    "https://www.seqrite.com/blog/operation-peek-a-baku-silent-lynx-apt-dushanbe-espionage",
    "https://otx.alienvault.com/pulse/690b44c86b05bcee7cf13cf6"
  ]
}