OctLurk and SilkLurk Alert: Suspected Chinese-speaking group targets Central Asian government

A new cyberattack campaign attributed to a Chinese-speaking threat actor is currently targeting multiple government organizations in Central Asia and several surrounding regions. According to The Hacker News citing Kaspersky analysis, this activity has been going on since January 2025 and focused on targets in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria.

The notable point lies not only in the geographical scope, but also in the set of tools designed to be deeply embedded in the system. The two new backdoors are named OctLurk and SilkLurk, comes with utilities LurkProxy used to forward network traffic. This way of operating shows that attackers prioritize the ability to hide, expand access and maintain control long after intrusion.

Trung tâm điều hành an ninh mạng minh họa cho chiến dịch OctLurk và SilkLurk

The campaign targets many public sectors

The noted targets span many sectors, including healthcare, research, government offices, state departments, logistics, law enforcement, urban planning, facilities management and public education. These are all groups of organizations that often hold sensitive data on administration, personnel, infrastructure and foreign relations.

According to Kaspersky, the activity is not currently firmly attributed to a known group. However, the infrastructure footprint intersects with an earlier campaign using a C++ implant called SilentRaid, also known by the names MystRodX or TrustFall. This overlap is not enough to conclude that the two campaigns were run by the same group, but suggests the possibility of reuse or sharing of infrastructure.

OctLurk operates primarily in memory

OctLurk is deployed through the loader and injected into memory, reducing the disk footprint. After running, the malicious code collects system information, encrypts the data and sends it to the control server. This backdoor can receive plugins from the server and load them directly into memory to perform many post-intrusion operations.

Functions described include command execution, file system manipulation, clipboard collection or editing, screen capture, mouse control, intranet scanning, login information extraction, and password theft from browsers. The attacker was also recorded using the Impacket tool to collect password hashes from domain controllers, deploying keyloggers impersonating AnyDesk and setting up remote access using Pandora RC agent.

LurkProxy opens the way for horizontal scrolling

LurkProxy acts as a reverse proxy, can operate in SOCKS5 or transparent proxy mode. In the context of attacks on large organizations, internal proxies help attackers route traffic through controlled machines, hide the real source of traffic, and access services that are not publicly available on the internet.

This is especially dangerous on state agency networks, where many systems are designed for internal access only. When a workstation or intermediate server is turned into a relay point, the protective boundary between the external network and the internal network can be partially disabled.

SilkLurk uses DLL side-loading and additional plugins

SilkLurk is launched via DLL side-loading, a technique that exploits legitimate processes to load malicious libraries. After connecting to the control server, the backdoor sends victim information and receives execution commands. It can change configuration, adjust server communication intervals, and receive additional plugins for memory injection.

SilkLurk's post-intrusion activities include using PowerShell to connect to shared resources with administrative information, searching for sensitive documents, packaging data using WinRAR or 7-Zip, and then preparing for a data leak. Kaspersky also noted a side-loading DLL chain that can drop PlugX, a backdoor that has appeared in many campaigns involving Chinese hacker groups.

Things to keep in mind for organizations

The OctLurk and SilkLurk campaigns highlight a familiar trend: modern malware increasingly restricts writing data to the drive, relies on dynamic loading plugins, and uses each machine's unique information to decode payloads. This approach makes automated analysis more difficult and reduces the effectiveness of measures based solely on file signatures.

Organizations should prioritize monitoring for post-intrusion behavior such as unusual logon event queries, Impacket usage in Windows environments, bulk access to network shares, legitimate processes loading strange DLLs, PowerShell creating data archives, and unusual proxy traffic between network segments. Besides, limiting administrative rights, separating the network and controlling login information stored in the browser is still a basic but very important layer of defense.

For public agencies and critical infrastructure operators, the key is not just to find malicious files, but to track the chain of behavior. As backdoors operate primarily in memory, authentication logs, EDRs, DNS monitoring, proxies, and process inventories become important sources of evidence for early detection.

VNCyberS compiled from The Hacker News and Kaspersky Securelist

Contact Us

Email: [email protected]
Phone: +84 903260277