DEV Community

Mark0
Mark0

Posted on

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Kaspersky researchers have identified a sophisticated cyber-espionage campaign active since January 2025, targeting government and critical infrastructure across Central Asia and Syria. The campaign utilizes two newly discovered backdoors, OctLurk and SilkLurk, which are characterized by their victim-specific obfuscation techniques. These loaders use machine-specific identifiers, such as drive serial numbers or computer names, to decrypt payloads directly into memory, making automated analysis and generic detection significantly more difficult.

The threat actor, assessed with medium confidence to be Chinese-speaking, deploys a comprehensive toolkit including the LurkProxy utility, credential harvesters, and secondary payloads like PlugX. The attack lifecycle involves maintaining persistence through scheduled tasks and Windows services, followed by extensive internal network scanning and sensitive data exfiltration. By combining customized backdoors with modular plugins, the attackers maintain high flexibility and redundancy within compromised environments.


Read Full Article

Top comments (0)