Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Attacks Hit Central Asia Using New Malware Tools

Cyber Attacks Hit Central Asia Using New Malware Tools

Posted on July 31, 2026 By CWS

Government entities in Central Asia, including those in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, have been targeted by cyber attacks since January 2025. These attacks, attributed to a Chinese-speaking threat actor, employ new sophisticated malware tools, as reported by Kaspersky.

Targets and Sectors Affected

The attacks have impacted various sectors such as healthcare, research, government offices, foreign affairs ministries, logistics, law enforcement, urban planning, and education. Despite the widespread targeting, the specific group responsible has not been identified, according to the Russian cybersecurity firm.

The cyber operation utilizes two newly discovered backdoors, named OctLurk and SilkLurk, alongside a utility called LurkProxy, designed to facilitate network traffic proxying. This advanced malware setup suggests a high level of sophistication in the ongoing attacks.

Malware Mechanisms and Intrusion Techniques

The malware tools OctLurk and SilkLurk are engineered to perform a range of malicious activities, including downloading additional plugins for executing command shells, file operations, and credential theft. Researchers Saurabh Sharma and Yaroslav Kikel of Kaspersky highlight their capabilities in conducting network scans and keylogging.

While the exact method of initial access remains unidentified, it is known that OctLurk is memory-injected and initiates operations by checking connectivity to a specific domain before deploying LurkProxy. This tool then contacts a remote server for command-and-control purposes, enabling further actions on the compromised systems.

Post-Compromise Activities and Threat Actor Tactics

Once activated, OctLurk collects and encrypts system information, transmitting it to a command server. It is capable of loading and executing plugins in memory, facilitating data collection and remote access. The threat actors exploit these tools to gather host information, harvest passwords, and establish unauthorized network connections.

SilkLurk, on the other hand, operates through a DLL side-loading mechanism, establishing a TCP socket to communicate with a control server. This interaction allows the attackers to execute commands, manage backdoor configurations, and inject additional plugins.

Kaspersky has identified infrastructure overlaps between these attacks and previous campaigns involving a C++ implant known as SilentRaid. This suggests a shared infrastructure, though the timeline and concurrency of these operations remain uncertain.

The constant evolution of the OctLurk and SilkLurk malware frameworks underscores the persistent efforts of threat actors to enhance their evasion techniques and maintain influence over compromised networks. By primarily operating in memory and using victim-specific encoding, these tools pose significant challenges to reverse engineering and automated detection.

The Hacker News Tags:Backdoors, Central Asia, cyber attacks, cyber threat, Cybersecurity, data security, government security, hacker groups, Kaspersky, Malware, network security, OctLurk, remote access, SilkLurk

Post navigation

Previous Post: North Korean Cyber Campaign Targets Crypto Wallets
Next Post: AI Dependency in Incident Response Plans

Related Posts

GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards The Hacker News
New Cyber Threat OP-512 Hits Microsoft IIS Servers New Cyber Threat OP-512 Hits Microsoft IIS Servers The Hacker News
Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with 0K in Rewards Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards The Hacker News
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor The Hacker News
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited The Hacker News
Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark