< Back to all clusters
[TECHNOLOGY] · Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan · 5 sources

started · updated

Chinese-speaking threat actors deploy OctLurk and SilkLurk against Central Asian government agencies

Since January 2025, a Chinese‑speaking threat actor has been conducting a wave of cyber‑attacks against government organisations in Central Asia and the Syrian Arab Republic. Targets include ministries, health and research bodies, law‑enforcement agencies and other public institutions in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria.

The attackers use two newly‑identified, heavily obfuscated backdoors – OctLurk and SilkLurk – together with a proxy tool called LurkProxy. Both malware families run in memory, can download additional plugins and perform actions such as command‑shell execution, credential dumping, keylogging, password theft from browsers, screenshot capture and remote file access. Kaspersky Lab researchers Saurabh Sharma and Yaroslav Kikel reported that OctLurk is injected via a loader and contacts a hard‑coded C2 server (IP 154.196.162.76), while SilkLurk is delivered through DLL side‑loading. No attribution to a known hacking group has been established.

Entities

Central Asian governments · Chinese-speaking threat actors · Kaspersky Lab · OctLurk · SilkLurk