Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    I’ve Waited 8 Years for Overwatch’s D.Mon. Her Gameplay Didn’t Disappoint

    August 7, 2026

    Our Favorite Fans Are on Sale to Help With Summer Heat Waves (2026)

    August 7, 2026

    What Chocolate Finance got right about S’pore’s changing savings habits

    August 7, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
    Cybersecurity

    Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

    InfoForTechBy InfoForTechAugust 1, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

    These targeted organizations operate across several sectors, such as healthcare, research, government offices, ministries of foreign affairs, logistics, law-enforcement agencies, urban planning and facilities management, and public educational establishments, per Kaspersky. The activity has not been linked to any known adversary or group.

    The attacks are characterized by the use of two new obfuscated backdoors the Russian cybersecurity company is tracking as OctLurk and SilkLurk, as well as a specialized utility codenamed LurkProxy to proxy network traffic.

    “OctLurk and SilkLurk can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access,” researchers Saurabh Sharma and Yaroslav Kikel said.

    The initial access vector used in these attacks is currently unknown. However, Kaspersky’s analysis has found that OctLurk is injected into memory and deployed by means of a loader, with the attackers also checking internet connectivity to the domain “dns.ssentialserv[.]xyz” before executing a batch script responsible for launching LurkProxy. The tool then establishes contact with a remote server (“154.196.162[.]76”) for command-and-control (C2).

    Once run, OctoLurk first collects system information, encrypts it, and sends it to a hard-coded C2 server (“dns.multitoconference[.]com”) over a stream socket connection. It’s equipped to load plugins received from the server directly into memory to enable command execution, file operations, clipboard content gathering and modification, screenshot capture, and mouse movements.

    The threat actors have been found to leverage the backdoor’s command shell plugin to perform the following series of actions –

    • Fingerprint the host and harvest extensive data about the compromised system.
    • Run commands to export successful logon events for remote interactive logons and to query those events for specific users.
    • Harvest password hashes from domain controllers using Impacket’s “secretsdump.py” tool.
    • Drop and execute a keylogger that masquerades as AnyDesk to sidestep detection.
    • Decrypt and extract passwords from Google Chrome and Mozilla Firefox.
    • Establish remote access to the victim machine using Pandora RC agent.
    • Scan internal and public networks using Fscan to identify services running on specific ports, such as Secure Shell (SSH) on port 22 and MySQL on port 3306, and then attempt to access these services using credentials from a password file named “pp.txt.”
    • Connect to an email server, authenticate with a username and password, and issue commands to collect or manipulate emails.

    LurkProxy, for its part, can function as a reverse proxy in two distinct modes, either as a SOCKS5 proxy or a transparent proxy. At any given time, the malware can operate in only one mode to route network traffic through a target address.

    The third tool in the threat actor’s arsenal is SilkLurk, which is launched by means of a DLL that, in turn, is executed using a DLL side-loading sequence. The backdoor then creates a TCP socket and connects to a C2 server specified in its configuration, followed by collecting victim information and transmitting it to the server.

    In response, the server sends a command that’s to be executed on the infected endpoint. This can involve getting the system’s local time, setting a sleep interval that determines the frequency at which the backdoor polls the C2 server, sending or updating backdoor configuration, and receiving and injecting additional plugins into memory.

    The post-compromise activity linked to SilkLurk is below –

    • Invoke “cmd.exe” to launch PowerShell and run commands to connect to shared network resources with administrative credentials, search and stage confidential documents, disconnect from the network shares, and use legitimate archiving tools like WinRAR and 7-Zip to archive the stolen data.
    • Run “cmd.exe” to initiate a DLL side-loading chain to drop PlugX, a known backdoor used by Chinese hacking groups.

    Kaspersky said it found infrastructure overlaps between the campaign and a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall).

    “This overlap points to shared infrastructure across multiple OS-targeting campaigns, though it remains unclear whether these activities ran concurrently or at different times,” Kaspersky said. “The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks.”

    “Both families operate primarily in memory, leaving only a minimalistic loader on disk that relies on machine-specific data (OctLurk uses the drive serial number, and SilkLurk uses the computer name) to decode payload locations and contents. This victim-specific encoding makes reverse engineering and automated detection considerably harder.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    August 7, 2026

    ChatGPT Atlas Shuts Down Aug. 9: What Users Must Save Before Migrating

    August 7, 2026

    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

    August 6, 2026

    Apple briefly removes Telegram from App Store over reported CSAM violation

    August 6, 2026

    Detect East-West Traffic Threats with Fidelis Network

    August 5, 2026

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    August 5, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.