

The malicious YoroTrooper in disguise. [Research Saturday]
Nov 18, 2023
Asheer Malhotra from Cisco Talos discusses their research on the espionage-focused threat actor YoroTrooper, attributing their work to individuals in Kazakhstan. YoroTrooper disguises its attacks as coming from Azerbaijan using VPN exit nodes. They heavily rely on phishing emails to direct victims to credential harvesting sites. The podcast also explores Eurotrooper's espionage and data theft activities, legacy sim challenges, YoroTrooper's aggressive tactics in targeting government entities and the energy sector, and the notion of persistence vs sophistication in espionage operations.
Chapters
Transcript
Episode notes