A suspected Chinese speaking threat actor has been linked to a new cyber campaign targeting government organizations across Central Asia since January 2025. According to findings published by Kaspersky, the attacks have primarily affected organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. The targeted entities span multiple sectors, including healthcare, research institutions, government departments, ministries of foreign affairs, logistics organizations, law enforcement agencies, urban planning offices, facilities management, and public educational institutions. Although the campaign has not yet been attributed to any known threat group, researchers identified two previously undocumented malware families named OctLurk and SilkLurk, along with a supporting utility called LurkProxy, which together provide attackers with a flexible framework for maintaining access to compromised systems and carrying out espionage activities.
Kaspersky researchers Saurabh Sharma and Yaroslav Kikel reported that both OctLurk and SilkLurk support modular plugins that significantly expand their capabilities after infection. These plugins allow attackers to execute command shells, perform file system operations, scan networks, capture screenshots, log keystrokes, steal passwords from browsers, dump credentials, collect emails, manipulate clipboard contents, generate keyboard and mouse activity, and establish remote access to compromised machines. While the initial infection method remains unknown, investigators determined that OctLurk is loaded directly into memory through a dedicated loader that first checks connectivity with a remote domain before executing a batch script that launches LurkProxy. The utility then establishes communication with its command and control infrastructure before OctLurk collects system information, encrypts the gathered data, and transmits it to another command server through an encrypted socket connection. From there, additional malicious plugins are delivered directly into memory without leaving substantial traces on disk, allowing attackers to expand functionality while reducing the likelihood of detection.
Researchers observed the attackers carrying out extensive post compromise activity once access had been established. The malware was used to fingerprint infected systems, gather detailed host information, export successful remote logon records, and identify specific user accounts. Threat actors also harvested password hashes from domain controllers using the Impacket tool secretsdump.py, deployed a keylogger disguised as AnyDesk to avoid suspicion, extracted saved credentials from Google Chrome and Mozilla Firefox, and established remote access through the Pandora RC agent. Additional reconnaissance included scanning internal and external networks using Fscan to identify services such as Secure Shell on port 22 and MySQL on port 3306 before attempting authentication with credentials stored in a password file. The malware also connected to email servers using compromised credentials to collect or manipulate email content. LurkProxy itself functioned either as a SOCKS5 proxy or as a transparent proxy, enabling attackers to route network traffic through compromised systems. SilkLurk followed a separate execution chain involving DLL side loading before establishing communication with its command server, collecting victim information, and receiving commands to retrieve system time, adjust operational intervals, update configurations, and load additional plugins directly into memory. Investigators also found that SilkLurk executed PowerShell commands to access shared network resources, identify confidential documents, archive stolen data using legitimate tools such as WinRAR and 7 Zip, and initiate another DLL side loading sequence that deployed the PlugX backdoor commonly associated with Chinese cyber operations.
Kaspersky also identified infrastructure overlaps between this campaign and earlier attacks involving a C++ implant known as SilentRaid, also tracked as MystRodX and TrustFall. While researchers could not determine whether both campaigns were conducted simultaneously or at different times, they noted that the shared infrastructure suggests a possible operational relationship. The company emphasized that both OctLurk and SilkLurk rely heavily on in memory execution, leaving only lightweight loaders on infected systems. Those loaders use machine specific information such as drive serial numbers or computer names to decode malware payloads, making reverse engineering and automated detection significantly more difficult. According to Kaspersky, the campaign demonstrates how threat actors continue refining malware frameworks to evade security controls, maintain long term access to compromised environments, and execute complex cyber espionage operations against government institutions and other strategically important organizations.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.