< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

3 clusters · 8 sources · 23 days · First seen · Last updated

Chinese-nexus cyber espionage in Central Asia and Azerbaijan

Overview

Since early 2025, a series of cyber espionage campaigns attributed to Chinese-nexus threat actors has targeted government institutions in Central Asia and surrounding regions.

Initial activity involved the deployment of heavily obfuscated backdoors known as OctLurk and SilkLurk, alongside a proxy tool called LurkProxy. These tools were used to target ministries, law enforcement, and health agencies in countries including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The malware was capable of credential dumping, keylogging, and remote file access.

The campaign has since evolved into an operation identified as SilkParasite. This phase utilizes a sophisticated arsenal of seven remote access tool (RAT) families, including five previously undocumented tools such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. This operation has expanded its scope to include the Azerbaijani energy sector, specifically targeting oil and gas infrastructure. Analysts note a strategic shift toward cross-platform capabilities, with payloads designed for Windows, Linux, and macOS to compromise IoT and OT gateways, potentially allowing lateral movement into critical industrial control systems.

Recent analysis links the campaign to the Chinese-nexus group FamousSparrow. Researchers have observed the professional use of artificial intelligence to streamline malware development and create phishing lures. One reported tactic involved using low-quality AI-generated content in phishing emails to blend in with common digital noise. To evade detection, attackers have routed command-and-control communications through legitimate cloud services like Google Drive. While the campaign targets various Central Asian nations, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, evidence also suggests targeting in Georgia. Unlike financially motivated ransomware, SilkParasite focuses on the long-term collection of strategic intelligence.

Entities

SilkParasite · Kaspersky Lab · Chinese-speaking threat actors · OctLurk · Central Asian governments

Timeline

  1. 23 days ago

    [TECHNOLOGY] 3 sources
    SilkParasite campaign targets Central Asian governments

    The SilkParasite cyber espionage campaign has targeted Central Asian governments for a year using seven malware families and AI-assisted techniques to collect strategic intelligence.

  2. 27 days ago

    [TECHNOLOGY] 5 sources
    SilkParasite cyber campaign targets Central Asian governments and Azerbaijani energy sector

    The SilkParasite cyber espionage campaign, linked to China-nexus actors, is targeting Central Asian governments and Azerbaijani energy infrastructure using advanced, cross-platform remote access tools.

  3. about 2 months ago

    [TECHNOLOGY] 5 sources
    Chinese-speaking threat actors deploy OctLurk and SilkLurk against Central Asian government agencies

    Since Jan 2025 Chinese‑speaking hackers have used new OctLurk and SilkLurk backdoors, plus LurkProxy, to breach Central Asian and Syrian government networks, stealing credentials and deploying plugins, Kaspersk

Sources

ad-hoc-news.de · borncity.com · businesstechweekly.com · cybernoz.com · cybersecuritynews.com · dev.to · flagthis.com · it-daily.net

This summary has been updated 1 time: see revision history