Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Attacks Hit Central Asia Using New Malware Tools

Cyber Attacks Hit Central Asia Using New Malware Tools

Posted on July 31, 2026 By CWS

Government entities in Central Asia, including those in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, have been targeted by cyber attacks since January 2025. These attacks, attributed to a Chinese-speaking threat actor, employ new sophisticated malware tools, as reported by Kaspersky.

Targets and Sectors Affected

The attacks have impacted various sectors such as healthcare, research, government offices, foreign affairs ministries, logistics, law enforcement, urban planning, and education. Despite the widespread targeting, the specific group responsible has not been identified, according to the Russian cybersecurity firm.

The cyber operation utilizes two newly discovered backdoors, named OctLurk and SilkLurk, alongside a utility called LurkProxy, designed to facilitate network traffic proxying. This advanced malware setup suggests a high level of sophistication in the ongoing attacks.

Malware Mechanisms and Intrusion Techniques

The malware tools OctLurk and SilkLurk are engineered to perform a range of malicious activities, including downloading additional plugins for executing command shells, file operations, and credential theft. Researchers Saurabh Sharma and Yaroslav Kikel of Kaspersky highlight their capabilities in conducting network scans and keylogging.

While the exact method of initial access remains unidentified, it is known that OctLurk is memory-injected and initiates operations by checking connectivity to a specific domain before deploying LurkProxy. This tool then contacts a remote server for command-and-control purposes, enabling further actions on the compromised systems.

Post-Compromise Activities and Threat Actor Tactics

Once activated, OctLurk collects and encrypts system information, transmitting it to a command server. It is capable of loading and executing plugins in memory, facilitating data collection and remote access. The threat actors exploit these tools to gather host information, harvest passwords, and establish unauthorized network connections.

SilkLurk, on the other hand, operates through a DLL side-loading mechanism, establishing a TCP socket to communicate with a control server. This interaction allows the attackers to execute commands, manage backdoor configurations, and inject additional plugins.

Kaspersky has identified infrastructure overlaps between these attacks and previous campaigns involving a C++ implant known as SilentRaid. This suggests a shared infrastructure, though the timeline and concurrency of these operations remain uncertain.

The constant evolution of the OctLurk and SilkLurk malware frameworks underscores the persistent efforts of threat actors to enhance their evasion techniques and maintain influence over compromised networks. By primarily operating in memory and using victim-specific encoding, these tools pose significant challenges to reverse engineering and automated detection.

The Hacker News Tags:Backdoors, Central Asia, cyber attacks, cyber threat, Cybersecurity, data security, government security, hacker groups, Kaspersky, Malware, network security, OctLurk, remote access, SilkLurk

Post navigation

Previous Post: North Korean Cyber Campaign Targets Crypto Wallets
Next Post: AI Dependency in Incident Response Plans

Related Posts

What Sets Top-Tier Platforms Apart? What Sets Top-Tier Platforms Apart? The Hacker News
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices The Hacker News
Adobe Reader Zero-Day Exploit Targets Users Since Late 2025 Adobe Reader Zero-Day Exploit Targets Users Since Late 2025 The Hacker News
Redis Security Flaws Lead to Critical Patches Redis Security Flaws Lead to Critical Patches The Hacker News
Empower Users and Protect Against GenAI Data Loss Empower Users and Protect Against GenAI Data Loss The Hacker News
New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Dependency in Incident Response Plans
  • Cyber Attacks Hit Central Asia Using New Malware Tools
  • North Korean Cyber Campaign Targets Crypto Wallets
  • HollowFrame and Matryoshka Backdoor Target Law Firm
  • AI Powers Google Chrome Security with 1,072 Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Dependency in Incident Response Plans
  • Cyber Attacks Hit Central Asia Using New Malware Tools
  • North Korean Cyber Campaign Targets Crypto Wallets
  • HollowFrame and Matryoshka Backdoor Target Law Firm
  • AI Powers Google Chrome Security with 1,072 Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark