Government organizations across Central Asia are facing a cyber espionage campaign that employs two newly identified malware families, OctLurk and SilkLurk, in attacks aimed at establishing long-term access to sensitive networks. Kaspersky said the activity has been ongoing since at least January 2025 and has affected organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and the Syrian Arab Republic. Victims span government ministries, foreign affairs departments, law enforcement agencies, healthcare organizations, research institutions, logistics providers, urban planning and facilities management offices, and public educational establishments. Although the campaign has not been tied to any known threat group, investigators believe a Chinese-speaking actor is behind the operation.
At the core of the campaign is a modular malware framework supported by LurkProxy, a custom utility that routes network traffic through compromised systems. The initial access method remains unknown, but investigators found that OctLurk is delivered through a lightweight loader that injects the backdoor directly into memory, checks internet connectivity, launches LurkProxy, and establishes communication with attacker-controlled command-and-control (C2) servers. The malware then gathers information about the infected device, encrypts the collected data, and retrieves plugins that are executed entirely in memory. This design allows the attackers to add capabilities as needed, including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation, network scanning, email collection, keylogging, credential dumping, browser password theft, and remote access, while leaving very little evidence on disk.
Analysis of the intrusions shows the operators moving quickly from reconnaissance to credential theft and lateral movement. The attackers exported Windows logon events to identify user activity, extracted password hashes from Active Directory domain controllers using Impacket's secretsdump.py, deployed a keylogger disguised as AnyDesk, recovered saved credentials from Google Chrome and Mozilla Firefox, and established remote access with Pandora RC. They also scanned internal and external networks with Fscan to identify services such as SSH and MySQL before attempting authentication with credentials stored in a password file. The campaign also involved connecting to email servers, accessing shared network resources with administrative credentials, collecting confidential documents, and compressing the staged data with WinRAR and 7-Zip before possible exfiltration.
SilkLurk expands the framework through DLL side-loading, creating a TCP connection with its configured C2 server before collecting victim information, receiving updated instructions, and loading additional plugins directly into memory. Investigators also found the malware deploying PlugX, a backdoor that has repeatedly appeared in Chinese cyber espionage operations. Kaspersky identified infrastructure overlaps with an earlier campaign involving the SilentRaid implant, also tracked as MystRodX and TrustFall, but said the available evidence is insufficient to confirm the same operators were responsible. Both OctLurk and SilkLurk rely on victim-specific decoding mechanisms derived from a system's drive serial number or computer name, making forensic analysis more difficult and allowing the malware to remain concealed while maintaining access to compromised government networks.
