Protect.Computer
NEWS

OctLurk and SilkLurk Backdoors Hit Central Asian Governments

· 1 min read · Got hacked Malicious byte
OctLurk and SilkLurk Backdoors Hit Central Asian Governments

Kaspersky researchers have documented a new cyber-espionage campaign active since at least January 2025 that is targeting government institutions, healthcare organizations, law-enforcement agencies, and universities across Central Asia — including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The activity has not been linked to any previously named threat actor, but its characteristics point toward a Chinese-speaking group. The campaign is notable for deploying two previously unseen memory-resident backdoors, which Kaspersky tracks as OctLurk and SilkLurk, along with a network-traffic proxy tool called LurkProxy.

Both backdoors are designed to evade detection by running almost entirely in memory rather than writing files to disk. OctLurk encrypts its payload using the target machine’s hard-drive serial number, while SilkLurk encodes data using the computer’s hostname — meaning captured malware samples cannot be analyzed on any other machine. Once running, each backdoor contacts a command-and-control server and accepts plugins that extend its capabilities to include keystroke logging, credential theft from browsers, screen capture, clipboard monitoring, file system browsing, and remote shell access. A third tool, LurkProxy, can relay traffic back to the attackers using either a SOCKS5 proxy or a transparent proxy, giving the group flexible network tunneling options. Kaspersky found infrastructure overlaps with a prior campaign using an implant called SilentRaid, suggesting the same operator has been running multi-OS operations for some time. The initial intrusion vector remains unknown. No patches are involved — this campaign uses custom malware rather than known vulnerabilities.

Sources

Related reading