News Room
16
Share
mediumState Cyber Warfare

State-Sponsored Cyber Operations Targeting Central Asia: A 2026 Assessment

An analysis of recent state-sponsored cyber activities in Central Asia, focusing on APT groups, their tactics, and the region's vulnerabilities.

₿

Encrygma is selling the entire Full Cyber Weapon Research of State-Sponsored Cyber Operations Targeting Central Asia: A 2026 Assessment for ₿ 0.10 BTC. Contact us.

01 April 2026Last updated 01 April 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Medium
Actor Type:
APT
Geography:
Central Asia
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

As of April 2026, Central Asia has become a focal point for state-sponsored cyber operations. Advanced Persistent Threat (APT) groups, often linked to nation-states, are increasingly targeting the region's critical infrastructure, government entities, and private sectors. This briefing examines recent activities, identifies key threat actors, and assesses the region's vulnerabilities.

Recent Cyber Operations in Central Asia

In late 2024, the APT group known as Silent Lynx initiated "Operation Peek-a-Baku," deploying phishing campaigns themed around regional diplomatic events. These campaigns delivered malicious attachments to government entities, financial institutions, and critical infrastructure sectors across Tajikistan, Kazakhstan, Kyrgyzstan, Turkmenistan, and Uzbekistan. The group's tactics included embedding malware within legitimate services, such as Google Drive and Windows Update, to evade detection. (hivepro.com)

Additionally, in 2020, an APT group believed to be state-sponsored infiltrated networks of a telecommunications company, a gas company, and a governmental institution in Central Asia. The attackers planted backdoors to maintain long-term access, monitoring operations and gathering sensitive information. (blog.avast.com)

Key Threat Actors

Several APT groups have been identified as active in the region:

  • Silent Lynx: Also known as YoroTrooper, Sturgeon Phisher, Cavalry Werewolf, and ShadowSilk, this group has been conducting sophisticated espionage campaigns across Central Asia since late 2024. (hivepro.com)

  • FontGoblin: A China-aligned APT group active since at least 2022, targeting government entities in Kyrgyzstan, Uzbekistan, Kazakhstan, and Pakistan. (eset.com)

  • FontFunkyGorillas: Another China-aligned APT group targeting various sectors in Eastern Europe and Central Asia, utilizing the Zmm backdoor and the Trochilus RAT. (eset.com)

Tactics, Techniques, and Procedures (TTPs)

State-sponsored APT groups employ a range of sophisticated TTPs:

  • Phishing Campaigns: Disguised as official communications, these campaigns deliver weaponized documents or links to gain initial access. (techradar.com)

  • Exploitation of Legitimate Services: Embedding malware within trusted platforms like Google Drive and Windows Update to evade detection. (techradar.com)

  • Supply Chain Attacks: Injecting malicious code into software updates or supply chain processes to compromise multiple targets simultaneously. (asec.ahnlab.com)

Regional Vulnerabilities

Central Asia's rapid digitalization has outpaced public digital literacy, creating an environment where cybercriminals exploit unprepared populations and weak institutional defenses. This digital vulnerability is exacerbated by limited cybersecurity infrastructure and a lack of coordinated regional response mechanisms. (anspistrategist.org)

Conclusion

The threat landscape in Central Asia is evolving, with state-sponsored APT groups increasingly targeting the region's critical infrastructure and institutions. To mitigate these threats, it is imperative for Central Asian nations to invest in robust cybersecurity measures, enhance public digital literacy, and foster regional cooperation to strengthen collective defense against cyber adversaries.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo