Kaspersky researchers have uncovered two new backdoors, OctLurk and SilkLurk, targeting government organizations in Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria) since January 2025. Both backdoors operate primarily in memory, use victim-specific encryption (OctLurk uses the C: drive serial number; SilkLurk uses the computer name) to decode payloads, and are heavily obfuscated. They support plugin injection for command shells, file management, keylogging, credential dumping, network scanning, browser password theft, and email harvesting. A companion tool, LurkProxy, provides SOCKS5 and transparent proxy capabilities. Post-compromise activity includes use of Impacket secretsdump, Pandora RC agent for remote access, FSCAN for network scanning, and PlugX as a second-stage payload. The threat actor is assessed with medium confidence to be Chinese-speaking, with infrastructure overlapping a previously reported Linux-targeting campaign (TrustFall/MystRodX/SilentRaid) in Kazakhstan.