Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Attacks Hit Central Asia Using New Malware Tools

Cyber Attacks Hit Central Asia Using New Malware Tools

Posted on July 31, 2026 By CWS

Government entities in Central Asia, including those in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, have been targeted by cyber attacks since January 2025. These attacks, attributed to a Chinese-speaking threat actor, employ new sophisticated malware tools, as reported by Kaspersky.

Targets and Sectors Affected

The attacks have impacted various sectors such as healthcare, research, government offices, foreign affairs ministries, logistics, law enforcement, urban planning, and education. Despite the widespread targeting, the specific group responsible has not been identified, according to the Russian cybersecurity firm.

The cyber operation utilizes two newly discovered backdoors, named OctLurk and SilkLurk, alongside a utility called LurkProxy, designed to facilitate network traffic proxying. This advanced malware setup suggests a high level of sophistication in the ongoing attacks.

Malware Mechanisms and Intrusion Techniques

The malware tools OctLurk and SilkLurk are engineered to perform a range of malicious activities, including downloading additional plugins for executing command shells, file operations, and credential theft. Researchers Saurabh Sharma and Yaroslav Kikel of Kaspersky highlight their capabilities in conducting network scans and keylogging.

While the exact method of initial access remains unidentified, it is known that OctLurk is memory-injected and initiates operations by checking connectivity to a specific domain before deploying LurkProxy. This tool then contacts a remote server for command-and-control purposes, enabling further actions on the compromised systems.

Post-Compromise Activities and Threat Actor Tactics

Once activated, OctLurk collects and encrypts system information, transmitting it to a command server. It is capable of loading and executing plugins in memory, facilitating data collection and remote access. The threat actors exploit these tools to gather host information, harvest passwords, and establish unauthorized network connections.

SilkLurk, on the other hand, operates through a DLL side-loading mechanism, establishing a TCP socket to communicate with a control server. This interaction allows the attackers to execute commands, manage backdoor configurations, and inject additional plugins.

Kaspersky has identified infrastructure overlaps between these attacks and previous campaigns involving a C++ implant known as SilentRaid. This suggests a shared infrastructure, though the timeline and concurrency of these operations remain uncertain.

The constant evolution of the OctLurk and SilkLurk malware frameworks underscores the persistent efforts of threat actors to enhance their evasion techniques and maintain influence over compromised networks. By primarily operating in memory and using victim-specific encoding, these tools pose significant challenges to reverse engineering and automated detection.

The Hacker News Tags:Backdoors, Central Asia, cyber attacks, cyber threat, Cybersecurity, data security, government security, hacker groups, Kaspersky, Malware, network security, OctLurk, remote access, SilkLurk

Post navigation

Previous Post: North Korean Cyber Campaign Targets Crypto Wallets
Next Post: AI Dependency in Incident Response Plans

Related Posts

LeakNet Ransomware Adopts ClickFix for Attacks LeakNet Ransomware Adopts ClickFix for Attacks The Hacker News
NIST Adjusts CVE Handling Amid Rising Submissions NIST Adjusts CVE Handling Amid Rising Submissions The Hacker News
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft The Hacker News
Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages The Hacker News
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms The Hacker News
Why SOC Burnout Can Be Avoided: Practical Steps Why SOC Burnout Can Be Avoided: Practical Steps The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Keycloak Security Flaw Exposes User Data Across Boundaries
  • AI Dependency in Incident Response Plans
  • Cyber Attacks Hit Central Asia Using New Malware Tools
  • North Korean Cyber Campaign Targets Crypto Wallets
  • HollowFrame and Matryoshka Backdoor Target Law Firm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Keycloak Security Flaw Exposes User Data Across Boundaries
  • AI Dependency in Incident Response Plans
  • Cyber Attacks Hit Central Asia Using New Malware Tools
  • North Korean Cyber Campaign Targets Crypto Wallets
  • HollowFrame and Matryoshka Backdoor Target Law Firm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark