A relatively new hacking group, known as YoroTrooper, is engaged in cyber espionage and is likely composed of hackers originating from Kazakhstan. Cisco Talos made this assumption by observing the group's activity. The researchers noted a fluency in Kazakh and Russian, and identified the use of Tenge to pay for operational infrastructure and a very limited targeting of Kazakh entities.

" YoroTrooper attempts to hide the origin of operations , using various tactics to make its malicious activity appear to originate from Azerbaijan. For example, it uses VPN exit nodes locally in that region its ," security researchers Asheer Malhotra and Vitor Ventura said .
The group was first detected in March 2023, but is believed to have been active since at least June 2022. Slovak cybersecurity firm ESET has been tracking the group's activity under the name SturgeonPhisher.
See also: Winter Vivern hackers use Roundcube zero-day to steal government emails
YoroTrooper hackers' attacks rely primarily on spear-phishing to distribute a combination of commodity and open source stealer malware to steal information. The group also often directs victims to credential harvesting controlled by the attackers.
“functions malware , with the ultimate goal of data theft,” the researchers said.
The public disclosure of the group's attacks prompted a revamp of its arsenal. Hackers turned to more custom malware based on Python, PowerShell, Golang, and Rust.
The YoroTrooper hackers' strong ties to Kazakhstan stem from the fact that the group regularly performs security scans of the state email service, mail[.]kz, indicating ongoing efforts to monitor the site for potential vulnerabilities .
It also periodically checks currency conversion rates between Tenge and Bitcoin on Google (“btc to kzt”) and uses alfachange[.]com to convert Tenge to Bitcoin and pay for infrastructure maintenance.
See also: Hackers target Russian organizations with backdoor to steal data
Since June 2023, the YoroTrooper group has been targeting countries in the Commonwealth of Independent States with specially tailored implants, while simultaneously using vulnerability scanners to identify vulnerabilities and penetrate victim.
Some of the targets included the Chamber of Commerce of Tajikistan, the Narcotics Control Service, the Ministry of Foreign Affairs, the KyrgyzKomur of Kyrgyzstan, and the Ministry of Energy of the Republic of Uzbekistan.

Cyber espionage: Ways to protect yourself
Cyber espionage poses a serious threat to both individuals and organizations. To protect themselves from cyber espionage, people and organizations can take a number of measures. One of these is awareness and education. Users need to be aware of the latest threats and techniques used by cyber spies, as well as the steps they can take to protect themselves. Educational programs and informational materials can help raise awareness and knowledge about the threats.
See also: Iranian OilRig hackers stayed in a Middle Eastern government network for 8 months
Another important security measure is to use strong passwords and change them regularly. Passwords should be unique and difficult for third parties to access. Using multi-factor authentication can also provide additional protection.
Additionally, installing up-to-date and reliable security is essential for protection.
Finally, protecting sensitive data is crucial. People and organizations need to be careful about how they store, transfer, and share their data. Encrypting data and using secure transmission methods can help protect against cyber espionage.
Source: thehackernews.com
