A suspected Chinese-speaking threat actor has been conducting a series of cyber attacks against government organizations in Central Asia since January 2025. The campaign, uncovered by Kaspersky, targets entities in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, across sectors including healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and public education.
The attackers deploy two new obfuscated backdoors—OctLurk and SilkLurk—alongside a utility called LurkProxy. These tools are designed to operate primarily in memory, leaving minimal traces on disk. OctLurk is injected via a loader and can download and execute plugins for command shells, file operations, keyboard and mouse synthesis, network scanning, credential dumping, keylogging, password theft, email collection, and remote access. SilkLurk is launched through DLL side-loading and similarly supports plugin injection, configuration updates, and command execution.
Initial access vectors remain unknown, but Kaspersky observed that OctLurk checks connectivity to a domain before executing a batch script that launches LurkProxy. LurkProxy functions as a reverse proxy in either SOCKS5 or transparent mode to route network traffic. Post-compromise activities include credential harvesting via Impacket’s secretsdump.py, keylogging disguised as AnyDesk, extracting passwords from Chrome and Firefox, establishing remote access with Pandora RC, scanning networks with Fscan, and exfiltrating data using WinRAR and 7-Zip. SilkLurk also drops PlugX, a known backdoor associated with Chinese hacking groups.
Kaspersky noted infrastructure overlaps with previous campaigns using the SilentRaid (MystRodX/TrustFall) implant, suggesting shared infrastructure across multiple operations. The use of victim-specific encoding—based on drive serial numbers for OctLurk and computer names for SilkLurk—complicates reverse engineering and automated detection.
CVEs: CVE-2026-50522
Attack groups: Chinese-speaking threat actor
Malware: OctLurk, SilkLurk, LurkProxy, PlugX, SilentRaid
Companies: Kaspersky
Products: AnyDesk, Pandora RC, Fscan, Impacket, WinRAR, 7-Zip
Original source: thehackernews.com