PULSE NAME
ShadowSilk: A Cross-Border Binary Union for Data Exfiltration.
WHITE PetrP.73 2025-08-28 Modified: 2025-09-27
68
IOCs
HIGH VOLUME
The group known as ShadowSilk has been identified as a cyber threat actor targeting government entities primarily in Central Asia and the Asia-Pacific (APAC) region since at least 2023, with ongoing activities detected through July 2025. ShadowSilk is connected to another group, YoroTrooper, sharing infrastructure and tools while operating as a distinct threat cluster. Analysis indicates that ShadowSilk's operations prioritize data exfiltration, having compromised over 35 victims mostly within the government sector. Technical assessments reveal that ShadowSilk employs a sophisticated arsenal, including public exploits, penetration-testing tools, and web panels acquired from dark web forums. These panels enable attackers to manage infected devices, upload files, and execute malicious code. Key elements of their toolkit include a web panel named Panel JLIB,
Indicators of Compromise (31 / 68 total)
All domain hostname FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 00bf14e8153778835f95b9255ae1658e37819f8d 2025-08-28
FileHash-SHA1 0135f8420c61babee43625dbba2a23ef9a12477d 2025-08-28
FileHash-SHA1 0279a25ee68fc23e91a353fbcd28f71c21e691fc 2025-08-28
FileHash-SHA1 04f2504f7f00f65e001709650affb90a86404e74 2025-08-28
FileHash-SHA1 11b0b620d0f0c4269a191d4ad9fd2042fb5e9d6c 2025-08-28
FileHash-SHA1 16bd4dc2befb4f64aaecf74818a347cd1a02c30d 2025-08-28
FileHash-SHA1 2cf77e48cf5699aac449c91552804e17edb04a71 2025-08-28
FileHash-SHA1 46bcac8ced15bf5bc1f2d9e463508273da6fa8e8 2025-08-28
FileHash-SHA1 471e1de3e1a7b0506f6492371a687cde4e278ed8 2025-08-28
FileHash-SHA1 488066ea37be17a8103d414c2593c7abb108ae95 2025-08-28
FileHash-SHA1 4d1426c0e04056396f8526a42afbb42f869db85b 2025-08-28
FileHash-SHA1 4e98b193d5539bf1ded86a6ddea696288f0a1a3e 2025-08-28
FileHash-SHA1 55d214fa9aa4d17cdd222f7deb4c5ec7e71ed4be 2025-08-28
FileHash-SHA1 5731274d1e7f0131e055ec34530f05ee603ef03b 2025-08-28
FileHash-SHA1 5e6254ebcf8ea518716c6090658b89960f425ab3 2025-08-28
FileHash-SHA1 7006ff7361522f36a25fabd9b91cf755c42c8cd7 2025-08-28
FileHash-SHA1 84fcc10fef6409c9f50d56bf4f17070b51149841 2025-08-28
FileHash-SHA1 85bb5a95db5b088b3e2f2c9f308b91d21d81e04d 2025-08-28
FileHash-SHA1 97bab01611d34ae97c368bd2c852f155b7286134 2025-08-28
FileHash-SHA1 9f4826cff6196b4a84fd9243fd6e6879c220b274 2025-08-28
FileHash-SHA1 b8ddc728483f1fe251d6ab64b401f297d993be39 2025-08-28
FileHash-SHA1 bcb1fd11b6b2f5046d4e5e8f714a8968d8a5d91d 2025-08-28
FileHash-SHA1 c02dd4d05a75e038c633d7d62669f2e1484f4b76 2025-08-28
FileHash-SHA1 c805c64a9e22f7ae3dea79f9215c60cdf32d87b8 2025-08-28
FileHash-SHA1 ca12e8975097d1591cda08d095d4af09b05da83f 2025-08-28
FileHash-SHA1 d840b0b3039be6cce673e6e07da5bd5e76628434 2025-08-28
FileHash-SHA1 dcb2d87b51de33f6d5fe53f777ad678c0af88a68 2025-08-28
FileHash-SHA1 ded2a5d2a7ebf3af1dc392c1af1e4b31fdc7cabc 2025-08-28
FileHash-SHA1 f385da641f2e506766a42dde81bb0fab13f845ee 2025-08-28
FileHash-SHA1 fb3db25d5dfe21e3c457756b8bd865c560323527 2025-08-28
FileHash-SHA1 fbbf624503001a981095356d1bd26bbf206a0df2 2025-08-28