A suspected Chinese-speaking threat actor has initiated a series of cyber attacks against government organizations primarily located in Central Asia. Countries affected include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These attacks have been ongoing since January 2025.
The targeted organizations span multiple sectors, such as healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and public educational establishments. The campaign utilizes two newly identified obfuscated backdoors, tracked by Kaspersky as OctLurk and SilkLurk, along with a utility called LurkProxy for network traffic proxying.
OctLurk and SilkLurk are designed to download and inject additional plugins, enabling a range of malicious activities. These include launching command shells, file system manipulation, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, browser password theft, email collection, and remote access. The initial access method for these attacks is currently unknown.
Kaspersky's analysis indicates that OctLurk is injected into memory via a loader. Attackers check internet connectivity to a specific domain before executing a batch script that launches LurkProxy, which then connects to a remote command-and-control (C2) server. OctLurk collects system information, encrypts it, and sends it to a hard-coded C2 server. It can load plugins directly into memory to execute commands, perform file operations, gather and modify clipboard content, capture screenshots, and control mouse movements.
Once established, the threat actors leverage the backdoor's command shell plugin to fingerprint the host and collect extensive data about the compromised system. They run commands to export successful logon events for remote interactive logons and query these events for specific users. Additionally, they harvest password hashes from domain controllers using Impacket's "secretsdump.py" tool and deploy a keylogger.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A Chinese-speaking threat actor has been targeting government organizations in Central Asia since January 2025, deploying new backdoors named OctLurk and SilkLurk. These attacks compromise various sectors, including healthcare and government ministries, to steal credentials and perform remote actions, highlighting an ongoing cyber espionage campaign.