Critical Ivanti EPMM Vulnerabilities Let Attackers Control Devices
Key Takeaways Government networks across Central Asia and Syria have been compromised by two sophisticated, custom-built backdoors: OctLurk and SilkLurk. The threat actor, believed to be...
Key Takeaways
- Government networks across Central Asia and Syria have been compromised by two sophisticated, custom-built backdoors: OctLurk and SilkLurk.
- The threat actor, believed to be Chinese-speaking, has been active since January 2025, targeting a wide array of public-sector organizations.
- These backdoors enable extensive control, including keystroke logging, password theft, email exfiltration, remote command execution, and network reconnaissance.
- Attackers leverage stolen credentials, malicious scheduled tasks, and services for persistence and lateral movement, exploiting a single compromised machine to access broader government infrastructure.
- Organizations must prioritize behavioral monitoring over file-based detection, scrutinize administrative account usage, and enhance vigilance for suspicious network activities to detect and mitigate these advanced threats.
Advanced Backdoors Target Central Asian Governments
Government agencies in Central Asia have fallen victim to a persistent cyber espionage campaign utilizing two bespoke backdoors, dubbed OctLurk and SilkLurk. These sophisticated tools afford attackers extensive control over infected systems, enabling them to log keystrokes, extract browser passwords, steal emails, and execute arbitrary commands remotely. The campaign, which has been active since January 2025, has impacted entities across Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria.
Table Of Content
Affected organizations span various critical sectors, including government ministries, law enforcement, healthcare providers, research institutions, logistics firms, educational establishments, and urban planning departments. According to a Securelist report, both malware families are attributed to a single, likely Chinese-speaking threat actor, though no specific known group has been formally linked to the operation.
The intrusion highlights a concerning trend where determined espionage groups can exploit a single compromised endpoint to gain deep access into vast government networks. Attackers have been observed using stolen administrator credentials, creating malicious scheduled tasks and services, and deploying additional tools to maintain persistent access and harvest sensitive information.
OctLurk: Stealthy Persistence and Broad Control
OctLurk is designed for covert operation and offers its operators a comprehensive suite of post-compromise capabilities. Its loader is uniquely tailored for each victim, employing machine-specific identifiers to decrypt and activate its final payload. This customization significantly complicates automated analysis and detection efforts.
Once established, OctLurk can dynamically load further plugins directly into memory, minimizing its disk footprint and making it harder for traditional security solutions to spot. These plugins empower attackers to perform critical actions such as browsing and exfiltrating files, opening command shells, capturing screenshots, reading clipboard data, conducting internal network scans, and simulating keyboard and mouse inputs.
The threat actors further augmented their data collection capabilities by deploying a keylogger and a browser password recovery utility. The keylogger diligently records keystrokes and clipboard contents locally, while the browser tool specifically targets stored credentials from popular browsers like Chrome and Firefox. This dual-pronged approach poses a severe risk to public-sector organizations, as a single compromised employee account can serve as a pivot point to access more critical systems.
Attackers also targeted domain controllers with password-dumping tools, aiming to acquire credentials that would facilitate broader lateral movement within the network. Of particular concern is their use of scheduled tasks, which are configured to run with elevated system privileges and are cunningly named to appear benign. This technique is a common method for attackers to ensure persistence across system restarts and initial incident response clean-up attempts.
OctLurk also includes a proxy component, enabling it to relay traffic through compromised devices. This functionality allows operators to reach internal systems not directly exposed to the internet, thereby reducing the likelihood of immediate detection of their activities.
SilkLurk: Expanding Espionage Capabilities
SilkLurk employs a distinct loading mechanism, masquerading within seemingly legitimate Windows programs and malicious DLL files. Its operational flow involves verifying the host program, decrypting its payload using the victim’s computer name, injecting the payload into memory, and establishing a persistent service.
Following initial access, the attackers utilized SilkLurk to systematically search shared network drives for confidential documents. Subsequently, they compressed the gathered files using archiving utilities, a standard preparatory step before exfiltrating data from an organization.
The campaign also saw the deployment of PlugX, a long-standing remote-access trojan frequently associated with various Chinese-linked advanced persistent threat (APT) operations. Researchers familiar with these tactics can refer to Chinese APT PlugX campaigns to understand how modular backdoors facilitate espionage through various means, including file exfiltration, screenshots, keystroke capture, and remote command execution.
What You Should Do
- Review Administrator Account Usage: Scrutinize all activities associated with administrator accounts for any anomalous behavior or unauthorized access attempts. Implement strict access controls and principle of least privilege.
- Investigate Unfamiliar Services and Scheduled Tasks: Regularly audit system services and scheduled tasks. Any entries that appear suspicious or are not officially sanctioned should be immediately investigated and, if malicious, removed.
- Monitor for Unusual Access: Implement continuous monitoring for unusual access patterns to critical assets such as domain controllers, browser credential stores, and shared network drives.
- Analyze Endpoint and Network Telemetry: Leverage endpoint detection and response (EDR) and network telemetry to identify the Indicators of Compromise (IoCs) provided below. Focus on behavioral anomalies rather than solely signature-based detection.
- Rotate Exposed Credentials: Immediately rotate any credentials that may have been compromised or exposed during an incident.
- Isolate Affected Hosts: During incident response, promptly isolate any identified compromised hosts to prevent further lateral movement and contain the threat.
- Enhance Behavioral Monitoring: Implement and refine security monitoring to focus on behavioral indicators such as new task creation, service installations, remote logons, and suspicious internal network scanning. This approach significantly improves the chances of detecting an intrusion before it escalates into a major compromise.
Indicators of Compromise (IoCs)
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
| Type | Indicator | Description |
|---|---|---|
| Domain | dns.ssentialserv[.]xyz | LurkProxy command-and-control domain |
| IP address | 154.196.162[.]76 | LurkProxy command-and-control server |
| Domain | dns.multitoconference[.]com | OctLurk command-and-control domain |
| Domain | gycudore.kozow[.]com | PlugX command-and-control domain |
| Domain | ctyuhjerf.kozow[.]com | SilkLurk command-and-control domain |
| IP address | 64.7.198[.]130 | PlugX command-and-control address |
| MD5 | 6ecf84fb18f6747ed08d7598364d853a | OctLurk deployment batch script |
| MD5 | 082d49ef9f14e6811d68c7e0e82e5069 | OctLurk loader DLL |
| MD5 | b874123a80fc4f40e06872b9cb54ebc6 | LurkProxy deployment batch script |
| MD5 | 45cf5916fab4272a1313c26e67aa9220 | Victim-fingerprinting batch script |
| MD5 | 4e6d5c4770d5a822d7fcce6a74f7ad73 | Victim-fingerprinting batch script |
| MD5 | 32a5985543433a4f60da2fafd873b927 | Credential-dumping executable |
| MD5 | 2a571f6cee42a17d873f4c942649813f | Keylogger executable |
| MD5 | 37dc84e4bcad92fa28f1e7778d088283 | Browser password decryptor |
| MD5 | 5e26df131ff0a679a0a2699b723b46e3 | Remote-control agent deployment script |
| MD5 | cf903e4a1629aa0582fd0363b5786676 | Fscan network-scanning tool |
| MD5 | 3c9a1ba8e0c7475706adc6376e9d7b7c | PlugX dropper |
| MD5 | 62944e26b36b1dcace429ae26ba66164 | PlugX sideloaded executable |
| MD5 | ef59aad625eebda8650aec5820d6ce69 | PlugX loader DLL |
| MD5 | be4731c09734da2e8eb6814a9c82f266 | SilkLurk loader DLL |
| MD5 | 7c2f64461bb519c6cbf1fc687675514c | OctLurk loader DLL |
| MD5 | f4578e869a735cfad691f927bae3e638 | OctLurk loader DLL |
| MD5 | 2f18472866f38c1e1c2c5c14b9a6ab56 | SilkLurk loader DLL |
| Filename | oleasapi.dll | OctLurk loader DLL |
| Filename | msbasesysdc.dll | LurkProxy loader DLL |
| Filename | Adobe.exe | Credential-dumping utility |
| Filename | OneDrive.dat | SilkLurk payload file |
| Filename | nvml.dll | SilkLurk loader DLL |
| Filename | vulkan-1.dll | SilkLurk loader DLL |
| Filename | RtkSmbusLoc.dll | SilkLurk loader DLL |
| Filename | RtkNGUI64Loc.dll | SilkLurk loader DLL |
| Filename | C.dll | PlugX loader DLL |
| Filename | C.dll.res | PlugX payload file |
| Filename | GoogleUpDate | Malicious scheduled task name |
| Filename | AnyDesk | Keylogger scheduled task name |
| Filename | NgcCIntSvc | OctLurk malicious service |
| Filename | Cusrxsrv | LurkProxy malicious service |
| Filename |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.