Securelist
Read post

OctLurk and SilkLurk: new Backdoors in Central Asia

Kaspersky researchers have uncovered two new backdoors, OctLurk and SilkLurk, targeting government organizations in Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria) since January 2025. Both backdoors operate primarily in memory, use victim-specific encryption (OctLurk uses the C: drive serial number; SilkLurk uses the computer name) to decode payloads, and are heavily obfuscated. They support plugin injection for command shells, file management, keylogging, credential dumping, network scanning, browser password theft, and email harvesting. A companion tool, LurkProxy, provides SOCKS5 and transparent proxy capabilities. Post-compromise activity includes use of Impacket secretsdump, Pandora RC agent for remote access, FSCAN for network scanning, and PlugX as a second-stage payload. The threat actor is assessed with medium confidence to be Chinese-speaking, with infrastructure overlapping a previously reported Linux-targeting campaign (TrustFall/MystRodX/SilentRaid) in Kazakhstan.

    #malware
Jul 30•29m read time•From securelist.com
Post cover image
Table of contents
IntroductionOctLurkSilkLurkInfrastructureAttributionConclusionsIndicators of Compromise
73 Impressions
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard