Wenn sich die Angreifer im Keyboard-Layout vertun:

ыскуут -ды ==> screen -ls
/дшые ==> /list

Aus einer Analyse zu #ShadowSilk
https://www.group-ib.com/blog/shadowsilk/

#ShadowSilk hackers just hit nearly 30+ gov targets across Central Asia & APAC.

The crew? A Russian-Chinese tag team using Telegram bots to hide C2 traffic + stealing Chrome passwords.

They’re still active—new victims found in July. #CyberSecurity #CyberAlerts https://thehackernews.com/2025/08/shadowsilk-hits-36-government-targets.html

ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram Bots

ShadowSilk hit 36 victims across Central Asia and APAC in July, using Telegram bots to exfiltrate government data.

The Hacker News