Cyberattacks Target Government Agencies in Central Asia Using New OctLurk and SilkLurk Malware

Views: 52 views

415/69 Monday, August 3, 2026

Since January 2025, reports have identified a new wave of cyberattacks carried out by an advanced threat group, primarily targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The affected entities span several nationally important sectors, including public health, research, foreign affairs ministries, law enforcement agencies, urban planning, logistics systems, and public educational institutions. This incident is significant because it targets government information infrastructure and enterprise-level networks.

Analysis found that the attackers used two new backdoor malware families, OctLurk and SilkLurk, along with a network traffic management tool called LurkProxy. Although the initial intrusion vector is still under investigation, these malware families are designed to operate mainly in system memory to evade detection. They can download additional plugins to perform various malicious activities, such as stealing passwords from web browsers, extracting password hashes from systems, capturing keystrokes, and enabling remote control of compromised machines. The attackers also use unique information from target computers, such as drive serial numbers or hostnames, as conditions for encrypting and hiding payload locations, making analysis and automated detection more difficult. In addition, they use legitimate file compression tools together with advanced malware such as PlugX to exfiltrate sensitive information.

This activity reflects the continued development of threat actor techniques to evade detection and maintain control over compromised networks. To prevent and reduce risk, users and network administrators should strengthen monitoring for abnormal behavior, especially network connections to unknown external domains or IP addresses. Initial measures should include deploying endpoint detection and response (EDR) solutions capable of detecting abnormal activity in memory, as well as regularly reviewing the use of system administration tools and software that may be abused. Enforcing strict access control policies can help organizations detect anomalies and respond to this emerging threat more effectively.

Source: https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html