Government entities in Central Asia, including those in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, have been targeted by cyber attacks since January 2025. These attacks, attributed to a Chinese-speaking threat actor, employ new sophisticated malware tools, as reported by Kaspersky.
Targets and Sectors Affected
The attacks have impacted various sectors such as healthcare, research, government offices, foreign affairs ministries, logistics, law enforcement, urban planning, and education. Despite the widespread targeting, the specific group responsible has not been identified, according to the Russian cybersecurity firm.
The cyber operation utilizes two newly discovered backdoors, named OctLurk and SilkLurk, alongside a utility called LurkProxy, designed to facilitate network traffic proxying. This advanced malware setup suggests a high level of sophistication in the ongoing attacks.
Malware Mechanisms and Intrusion Techniques
The malware tools OctLurk and SilkLurk are engineered to perform a range of malicious activities, including downloading additional plugins for executing command shells, file operations, and credential theft. Researchers Saurabh Sharma and Yaroslav Kikel of Kaspersky highlight their capabilities in conducting network scans and keylogging.
While the exact method of initial access remains unidentified, it is known that OctLurk is memory-injected and initiates operations by checking connectivity to a specific domain before deploying LurkProxy. This tool then contacts a remote server for command-and-control purposes, enabling further actions on the compromised systems.
Post-Compromise Activities and Threat Actor Tactics
Once activated, OctLurk collects and encrypts system information, transmitting it to a command server. It is capable of loading and executing plugins in memory, facilitating data collection and remote access. The threat actors exploit these tools to gather host information, harvest passwords, and establish unauthorized network connections.
SilkLurk, on the other hand, operates through a DLL side-loading mechanism, establishing a TCP socket to communicate with a control server. This interaction allows the attackers to execute commands, manage backdoor configurations, and inject additional plugins.
Kaspersky has identified infrastructure overlaps between these attacks and previous campaigns involving a C++ implant known as SilentRaid. This suggests a shared infrastructure, though the timeline and concurrency of these operations remain uncertain.
The constant evolution of the OctLurk and SilkLurk malware frameworks underscores the persistent efforts of threat actors to enhance their evasion techniques and maintain influence over compromised networks. By primarily operating in memory and using victim-specific encoding, these tools pose significant challenges to reverse engineering and automated detection.
