← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Chinese-Speaking Hackers Target Central Asian Governments with New OctLurk and SilkLurk Backdoors

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attacks target Central Asian governments since January 2025.
  • New backdoors, OctLurk and SilkLurk, are used.
  • Threat actors steal credentials and perform remote actions.
  • Initial access vector remains unknown.

New Cyber Campaign Targets Central Asia

A suspected Chinese-speaking threat actor has initiated a series of cyber attacks against government organizations primarily located in Central Asia. Countries affected include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These attacks have been ongoing since January 2025.

Affected Sectors and New Malware

The targeted organizations span multiple sectors, such as healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and public educational establishments. The campaign utilizes two newly identified obfuscated backdoors, tracked by Kaspersky as OctLurk and SilkLurk, along with a utility called LurkProxy for network traffic proxying.

Capabilities of OctLurk and SilkLurk

OctLurk and SilkLurk are designed to download and inject additional plugins, enabling a range of malicious activities. These include launching command shells, file system manipulation, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, browser password theft, email collection, and remote access. The initial access method for these attacks is currently unknown.

Operational Details and Data Exfiltration

Kaspersky's analysis indicates that OctLurk is injected into memory via a loader. Attackers check internet connectivity to a specific domain before executing a batch script that launches LurkProxy, which then connects to a remote command-and-control (C2) server. OctLurk collects system information, encrypts it, and sends it to a hard-coded C2 server. It can load plugins directly into memory to execute commands, perform file operations, gather and modify clipboard content, capture screenshots, and control mouse movements.

Post-Compromise Actions

Once established, the threat actors leverage the backdoor's command shell plugin to fingerprint the host and collect extensive data about the compromised system. They run commands to export successful logon events for remote interactive logons and query these events for specific users. Additionally, they harvest password hashes from domain controllers using Impacket's "secretsdump.py" tool and deploy a keylogger.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A Chinese-speaking threat actor has been targeting government organizations in Central Asia since January 2025, deploying new backdoors named OctLurk and SilkLurk. These attacks compromise various sectors, including healthcare and government ministries, to steal credentials and perform remote actions, highlighting an ongoing cyber espionage campaign.