Government networks across Central Asia have been infiltrated by two sophisticated backdoors, OctLurk and SilkLurk, granting attackers extensive control over compromised systems. These tools enable cybercriminals to log keystrokes, extract browser passwords, access emails, and execute remote commands.
Active since January 2025, the campaign has targeted organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria. Affected entities include ministries, law enforcement agencies, healthcare institutions, research centers, logistics firms, educational bodies, and urban planning departments.
Both malware families are attributed to a likely Chinese-speaking threat actor, though no specific group has been identified. The operation underscores the potential for a single compromised machine to serve as a gateway to broader governmental networks.
OctLurk: Stealthy and Modular
OctLurk is designed for stealth and flexibility post-infection. Its loader is tailored for each victim, utilizing machine-specific data to decrypt the final payload, complicating detection and analysis. Once activated, OctLurk can load additional plugins directly into memory, minimizing its on-disk footprint.
These plugins empower attackers to browse and exfiltrate files, open command shells, capture screenshots, monitor clipboard contents, perform network scans, and simulate user input. Additionally, a keylogger and a browser password recovery tool are employed to harvest credentials from compromised systems. The keylogger records keystrokes and clipboard data locally, while the browser tool targets stored credentials in Chrome and Firefox.
The attackers also deploy a password-dumping tool against domain controllers to obtain credentials facilitating lateral movement within the network. Their use of scheduled tasks, running with elevated privileges and named to appear legitimate, aids in maintaining persistent access.
SilkLurk: Concealed and Persistent
SilkLurk employs a different approach, masquerading as legitimate Windows applications and malicious DLL files. It verifies the host program, decrypts its payload using the victim’s computer name, injects it into memory, and establishes a service for persistence.
Post-infection, attackers use SilkLurk to search shared network drives for sensitive documents, which are then compressed using archiving utilities—a common precursor to data exfiltration. The campaign also utilizes PlugX, a longstanding remote-access trojan associated with various Chinese-linked operations, to enhance their espionage capabilities.
Defenders are advised to scrutinize administrator account activities, investigate unfamiliar services and scheduled tasks, and monitor access to domain controllers, browser credential stores, and shared drives. Reviewing endpoint and network telemetry for indicators of compromise, rotating exposed credentials, and isolating affected hosts are critical steps in incident response.
This campaign highlights the importance of behavior-based monitoring over reliance on static indicators, emphasizing the need for proactive and adaptive defense strategies against evolving cyber threats.