Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
3 clusters · 8 sources · 23 days · First seen · Last updated
Chinese-nexus cyber espionage in Central Asia and Azerbaijan
Overview
Since early 2025, a series of cyber espionage campaigns attributed to Chinese-nexus threat actors has targeted government institutions in Central Asia and surrounding regions.
Initial activity involved the deployment of heavily obfuscated backdoors known as OctLurk and SilkLurk, alongside a proxy tool called LurkProxy. These tools were used to target ministries, law enforcement, and health agencies in countries including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The malware was capable of credential dumping, keylogging, and remote file access.
The campaign has since evolved into an operation identified as SilkParasite. This phase utilizes a sophisticated arsenal of seven remote access tool (RAT) families, including five previously undocumented tools such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. This operation has expanded its scope to include the Azerbaijani energy sector, specifically targeting oil and gas infrastructure. Analysts note a strategic shift toward cross-platform capabilities, with payloads designed for Windows, Linux, and macOS to compromise IoT and OT gateways, potentially allowing lateral movement into critical industrial control systems.
Recent analysis links the campaign to the Chinese-nexus group FamousSparrow. Researchers have observed the professional use of artificial intelligence to streamline malware development and create phishing lures. One reported tactic involved using low-quality AI-generated content in phishing emails to blend in with common digital noise. To evade detection, attackers have routed command-and-control communications through legitimate cloud services like Google Drive. While the campaign targets various Central Asian nations, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, evidence also suggests targeting in Georgia. Unlike financially motivated ransomware, SilkParasite focuses on the long-term collection of strategic intelligence.
Entities
SilkParasite · Kaspersky Lab · Chinese-speaking threat actors · OctLurk · Central Asian governments
Timeline
-
23 days ago
[TECHNOLOGY] 3 sourcesSilkParasite campaign targets Central Asian governmentsThe SilkParasite cyber espionage campaign has targeted Central Asian governments for a year using seven malware families and AI-assisted techniques to collect strategic intelligence.
-
27 days ago
[TECHNOLOGY] 5 sourcesSilkParasite cyber campaign targets Central Asian governments and Azerbaijani energy sectorThe SilkParasite cyber espionage campaign, linked to China-nexus actors, is targeting Central Asian governments and Azerbaijani energy infrastructure using advanced, cross-platform remote access tools.
-
about 2 months ago
[TECHNOLOGY] 5 sourcesChinese-speaking threat actors deploy OctLurk and SilkLurk against Central Asian government agenciesSince Jan 2025 Chinese‑speaking hackers have used new OctLurk and SilkLurk backdoors, plus LurkProxy, to breach Central Asian and Syrian government networks, stealing credentials and deploying plugins, Kaspersk
Sources
ad-hoc-news.de · borncity.com · businesstechweekly.com · cybernoz.com · cybersecuritynews.com · dev.to · flagthis.com · it-daily.net
This summary has been updated 1 time: see revision history