Hydra Saiga is a suspected Kazakhstan-aligned, likely state-sponsored espionage threat actor active since at least 2021. It is also tracked as Yorotrooper, ShadowSilk, and Silent Lynx. The group has targeted government entities, energy organizations, and other critical infrastructure across Central Asia, Europe, and the Middle East, with operations aligned to regional geopolitical interests including water infrastructure and attempted access to industrial and gas-related environments. Hydra Saiga is characterized by espionage-focused intrusions that combine phishing-based initial access with extensive hands-on-keyboard post-compromise activity. Reported delivery methods include malicious loaders and macro-enabled lure documents. The actor uses both commodity tooling and custom implants implemented in PowerShell, Python, Go, and Rust. A defining operational pattern is the use of Telegram Bot API–based command and control, alongside broader reliance on living-off-the-land techniques after compromise. Observed post-exploitation behavior includes persistence through scheduled tasks and registry modification; credential access through LSASS dumping, export of SAM and SECURITY hives, enabling WDigest, and use of fake logon-screen tooling; lateral movement using domain discovery utilities together with WMI and PsExec; and defense evasion through disabling Microsoft Defender features and host firewall protections. The actor has also conducted reconnaissance with internet-exposed asset discovery and vulnerability-scanning platforms, collected screenshots and archived documents for theft, transferred tooling with native utilities, and exfiltrated data through scripted channels and browser-data stealing components. Hydra Saiga has been linked to compromises of dozens of organizations across multiple countries, with additional reconnaissance against a much broader victim set. Attribution to a Kazakhstani nexus has been supported by operator work-hour patterns consistent with UTC+5, inactivity on Kazakhstani holidays, and reported infrastructure and tooling overlap with the Tomiris cluster, including similarities involving JLORAT and Telemiris-related tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage/infiltration actor (reported as Kazakhstani) targeting sectors including energy and legal; uses custom implants (Rust/Go/Python) and living-off-the-land techniques; adapts to bypass modern defenses such as Chrome app-bound encryption.
State-aligned espionage/infiltration activity focused on government and critical utilities (notably water and energy) across Central Asia and beyond. Uses Telegram Bot API as a defining C2 channel, combines custom implants (Rust/Go/Python/PowerShell) with heavy hands-on-keyboard living-off-the-land post-exploitation, credential theft, lateral movement, and data exfiltration (including browser credential/cookie theft).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.