Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
DeepSeek-Powered Hermes Agent Autonomous Cyberattacks Target Exposed Servers
July 31, 2026
ShutterGap Flaw Exposes AWS Resources Between Security Scans
July 31, 2026
Critical SolarWinds Web Help Desk Flaw (CVE-2024-28925) Bypasses SAML Login
July 31, 2026
Home/Threats/Critical Ivanti EPMM Vulnerabilities Let Attackers Control Devices
Threats

Critical Ivanti EPMM Vulnerabilities Let Attackers Control Devices

Key Takeaways Government networks across Central Asia and Syria have been compromised by two sophisticated, custom-built backdoors: OctLurk and SilkLurk. The threat actor, believed to be...

Emy Elsamnoudy
Emy Elsamnoudy
July 31, 2026 5 Min Read
5 0

Key Takeaways

  • Government networks across Central Asia and Syria have been compromised by two sophisticated, custom-built backdoors: OctLurk and SilkLurk.
  • The threat actor, believed to be Chinese-speaking, has been active since January 2025, targeting a wide array of public-sector organizations.
  • These backdoors enable extensive control, including keystroke logging, password theft, email exfiltration, remote command execution, and network reconnaissance.
  • Attackers leverage stolen credentials, malicious scheduled tasks, and services for persistence and lateral movement, exploiting a single compromised machine to access broader government infrastructure.
  • Organizations must prioritize behavioral monitoring over file-based detection, scrutinize administrative account usage, and enhance vigilance for suspicious network activities to detect and mitigate these advanced threats.

Advanced Backdoors Target Central Asian Governments

Government agencies in Central Asia have fallen victim to a persistent cyber espionage campaign utilizing two bespoke backdoors, dubbed OctLurk and SilkLurk. These sophisticated tools afford attackers extensive control over infected systems, enabling them to log keystrokes, extract browser passwords, steal emails, and execute arbitrary commands remotely. The campaign, which has been active since January 2025, has impacted entities across Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria.

Table Of Content

  • Key Takeaways
  • Advanced Backdoors Target Central Asian Governments
  • OctLurk: Stealthy Persistence and Broad Control
  • SilkLurk: Expanding Espionage Capabilities
  • What You Should Do
  • Indicators of Compromise (IoCs)

Affected organizations span various critical sectors, including government ministries, law enforcement, healthcare providers, research institutions, logistics firms, educational establishments, and urban planning departments. According to a Securelist report, both malware families are attributed to a single, likely Chinese-speaking threat actor, though no specific known group has been formally linked to the operation.

The intrusion highlights a concerning trend where determined espionage groups can exploit a single compromised endpoint to gain deep access into vast government networks. Attackers have been observed using stolen administrator credentials, creating malicious scheduled tasks and services, and deploying additional tools to maintain persistent access and harvest sensitive information.

OctLurk: Stealthy Persistence and Broad Control

OctLurk is designed for covert operation and offers its operators a comprehensive suite of post-compromise capabilities. Its loader is uniquely tailored for each victim, employing machine-specific identifiers to decrypt and activate its final payload. This customization significantly complicates automated analysis and detection efforts.

Once established, OctLurk can dynamically load further plugins directly into memory, minimizing its disk footprint and making it harder for traditional security solutions to spot. These plugins empower attackers to perform critical actions such as browsing and exfiltrating files, opening command shells, capturing screenshots, reading clipboard data, conducting internal network scans, and simulating keyboard and mouse inputs.

The threat actors further augmented their data collection capabilities by deploying a keylogger and a browser password recovery utility. The keylogger diligently records keystrokes and clipboard contents locally, while the browser tool specifically targets stored credentials from popular browsers like Chrome and Firefox. This dual-pronged approach poses a severe risk to public-sector organizations, as a single compromised employee account can serve as a pivot point to access more critical systems.

Attackers also targeted domain controllers with password-dumping tools, aiming to acquire credentials that would facilitate broader lateral movement within the network. Of particular concern is their use of scheduled tasks, which are configured to run with elevated system privileges and are cunningly named to appear benign. This technique is a common method for attackers to ensure persistence across system restarts and initial incident response clean-up attempts.

OctLurk also includes a proxy component, enabling it to relay traffic through compromised devices. This functionality allows operators to reach internal systems not directly exposed to the internet, thereby reducing the likelihood of immediate detection of their activities.

SilkLurk: Expanding Espionage Capabilities

SilkLurk employs a distinct loading mechanism, masquerading within seemingly legitimate Windows programs and malicious DLL files. Its operational flow involves verifying the host program, decrypting its payload using the victim’s computer name, injecting the payload into memory, and establishing a persistent service.

Following initial access, the attackers utilized SilkLurk to systematically search shared network drives for confidential documents. Subsequently, they compressed the gathered files using archiving utilities, a standard preparatory step before exfiltrating data from an organization.

The campaign also saw the deployment of PlugX, a long-standing remote-access trojan frequently associated with various Chinese-linked advanced persistent threat (APT) operations. Researchers familiar with these tactics can refer to Chinese APT PlugX campaigns to understand how modular backdoors facilitate espionage through various means, including file exfiltration, screenshots, keystroke capture, and remote command execution.

What You Should Do

  • Review Administrator Account Usage: Scrutinize all activities associated with administrator accounts for any anomalous behavior or unauthorized access attempts. Implement strict access controls and principle of least privilege.
  • Investigate Unfamiliar Services and Scheduled Tasks: Regularly audit system services and scheduled tasks. Any entries that appear suspicious or are not officially sanctioned should be immediately investigated and, if malicious, removed.
  • Monitor for Unusual Access: Implement continuous monitoring for unusual access patterns to critical assets such as domain controllers, browser credential stores, and shared network drives.
  • Analyze Endpoint and Network Telemetry: Leverage endpoint detection and response (EDR) and network telemetry to identify the Indicators of Compromise (IoCs) provided below. Focus on behavioral anomalies rather than solely signature-based detection.
  • Rotate Exposed Credentials: Immediately rotate any credentials that may have been compromised or exposed during an incident.
  • Isolate Affected Hosts: During incident response, promptly isolate any identified compromised hosts to prevent further lateral movement and contain the threat.
  • Enhance Behavioral Monitoring: Implement and refine security monitoring to focus on behavioral indicators such as new task creation, service installations, remote logons, and suspicious internal network scanning. This approach significantly improves the chances of detecting an intrusion before it escalates into a major compromise.

Indicators of Compromise (IoCs)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Type Indicator Description
Domain dns.ssentialserv[.]xyz LurkProxy command-and-control domain
IP address 154.196.162[.]76 LurkProxy command-and-control server
Domain dns.multitoconference[.]com OctLurk command-and-control domain
Domain gycudore.kozow[.]com PlugX command-and-control domain
Domain ctyuhjerf.kozow[.]com SilkLurk command-and-control domain
IP address 64.7.198[.]130 PlugX command-and-control address
MD5 6ecf84fb18f6747ed08d7598364d853a OctLurk deployment batch script
MD5 082d49ef9f14e6811d68c7e0e82e5069 OctLurk loader DLL
MD5 b874123a80fc4f40e06872b9cb54ebc6 LurkProxy deployment batch script
MD5 45cf5916fab4272a1313c26e67aa9220 Victim-fingerprinting batch script
MD5 4e6d5c4770d5a822d7fcce6a74f7ad73 Victim-fingerprinting batch script
MD5 32a5985543433a4f60da2fafd873b927 Credential-dumping executable
MD5 2a571f6cee42a17d873f4c942649813f Keylogger executable
MD5 37dc84e4bcad92fa28f1e7778d088283 Browser password decryptor
MD5 5e26df131ff0a679a0a2699b723b46e3 Remote-control agent deployment script
MD5 cf903e4a1629aa0582fd0363b5786676 Fscan network-scanning tool
MD5 3c9a1ba8e0c7475706adc6376e9d7b7c PlugX dropper
MD5 62944e26b36b1dcace429ae26ba66164 PlugX sideloaded executable
MD5 ef59aad625eebda8650aec5820d6ce69 PlugX loader DLL
MD5 be4731c09734da2e8eb6814a9c82f266 SilkLurk loader DLL
MD5 7c2f64461bb519c6cbf1fc687675514c OctLurk loader DLL
MD5 f4578e869a735cfad691f927bae3e638 OctLurk loader DLL
MD5 2f18472866f38c1e1c2c5c14b9a6ab56 SilkLurk loader DLL
Filename oleasapi.dll OctLurk loader DLL
Filename msbasesysdc.dll LurkProxy loader DLL
Filename Adobe.exe Credential-dumping utility
Filename OneDrive.dat SilkLurk payload file
Filename nvml.dll SilkLurk loader DLL
Filename vulkan-1.dll SilkLurk loader DLL
Filename RtkSmbusLoc.dll SilkLurk loader DLL
Filename RtkNGUI64Loc.dll SilkLurk loader DLL
Filename C.dll PlugX loader DLL
Filename C.dll.res PlugX payload file
Filename GoogleUpDate Malicious scheduled task name
Filename AnyDesk Keylogger scheduled task name
Filename NgcCIntSvc OctLurk malicious service
Filename Cusrxsrv LurkProxy malicious service
Filename

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Anthropic Claude Vulnerability Exposed 3 Organizations’ Data

Next Post

CMMC Phase 2 Paused, Contractors Must Still Meet Data Security Obligations

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
PHP Patches Critical SQL Injection, Memory Corruption Flaws
July 31, 2026
Gentlemen Ransomware Terminates 180 Security Processes Before Encryption
July 31, 2026
CMMC Phase 2 Paused, Contractors Must Still Meet Data Security Obligations
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us