Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Amazon is splitting its $600 million tariff refund with customers – here’s who’s eligible

    July 31, 2026

    CareCloud Data Breach Impacts Over 350,000

    July 31, 2026

    Bitcoin (BTC) price’s July gain survives hawkish Fed, AI meltdown and Coldcard fallout

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Amazon is splitting its $600 million tariff refund with customers – here’s who’s eligible
    • CareCloud Data Breach Impacts Over 350,000
    • Bitcoin (BTC) price’s July gain survives hawkish Fed, AI meltdown and Coldcard fallout
    • Indigenous Parakanã fear election U-turn may spark new invasions in Brazil
    • France’s Wildfires Are Swallowing Its Politics
    • The NHS isn’t offering Premier League match tickets as a treatment for depression – Full Fact
    • Body of US climber Mallory Geis found after Broad Peak avalanche
    • Labour wins decisive victory in Greater Manchester mayoral byelection | Mayoral elections
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, July 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 31, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

    These targeted organizations operate across several sectors, such as healthcare, research, government offices, ministries of foreign affairs, logistics, law-enforcement agencies, urban planning and facilities management, and public educational establishments, per Kaspersky. The activity has not been linked to any known adversary or group.

    The attacks are characterized by the use of two new obfuscated backdoors the Russian cybersecurity company is tracking as OctLurk and SilkLurk, as well as a specialized utility codenamed LurkProxy to proxy network traffic.

    “OctLurk and SilkLurk can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access,” researchers Saurabh Sharma and Yaroslav Kikel said.

    Cybersecurity

    The initial access vector used in these attacks is currently unknown. However, Kaspersky analysis has found that OctLurk is injected into memory and deployed by means of a loader, with the attackers also checking internet connectivity to the domain “dns.ssentialserv[.]xyz” before executing a batch script responsible for launching LurkProxy. The tool then establishes contact with a remote server (“154.196.162[.]76”) for command-and-control (C2).

    Once run, OctoLurk first collects system information, encrypts it, and sends it to a hard-coded C2 server (“dns.multitoconference[.]com”) over a stream socket connection. It’s equipped to load plugins received from the server directly into memory to enable command execution, file operations, clipboard content gathering and modification, screenshot capture, and mouse movements.

    The threat actors have been found to leverage the backdoor’s command shell plugin to perform the following series of actions –

    • Fingerprint the host and harvest extensive data about the compromised system.
    • Run commands to export successful logon events for remote interactive logons and to query those events for specific users.
    • Harvest password hashes from domain controllers using Impacket’s “secretsdump.py” tool.
    • Drop and execute a keylogger that masquerades as AnyDesk to sidestep detection.
    • Decrypt and extract passwords from Google Chrome and Mozilla Firefox.
    • Establish remote access to the victim machine using Pandora RC agent.
    • Scan internal and public networks using Fscan to identify services running on specific ports, such as Secure Shell (SSH) on port 22 and MySQL on port 3306, and then attempt to access these services using credentials from a password file named “pp.txt.”
    • Connect to an email server, authenticate with a username and password, and issue commands to collect or manipulate emails.

    LurkProxy, for its part, can function as a reverse proxy in two distinct modes, either as a SOCKS5 proxy or a transparent proxy. At any given time, the malware can operate in only one mode to route network traffic through a target address.

    The third tool in the threat actor’s arsenal is SilkLurk, which is launched by means of a DLL that, in turn, is executed using a DLL side-loading sequence. The backdoor then creates a TCP socket and connects to a C2 server specified in its configuration, followed by collecting victim information and transmitting it to the server.

    In response, the server sends a command that’s to be executed on the infected endpoint. This can involve getting the system’s local time, setting a sleep interval that determines the frequency at which the backdoor polls the C2 server, sending or updating backdoor configuration, and receiving and injecting additional plugins into memory.

    Cybersecurity

    The post-compromise activity linked to SilkLurk is below –

    • Invoke “cmd.exe” to launch PowerShell and run commands to connect to shared network resources with administrative credentials, search and stage confidential documents, disconnect from the network shares, and use legitimate archiving tools like WinRAR and 7-Zip to archive the stolen data.
    • Run “cmd.exe” to initiate a DLL side-loading chain to drop PlugX, a known backdoor used by Chinese hacking groups.

    Kaspersky said it found infrastructure overlaps between the campaign and a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall).

    “This overlap points to shared infrastructure across multiple OS-targeting campaigns, though it remains unclear whether these activities ran concurrently or at different times,” Kaspersky said. “The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks.”

    “Both families operate primarily in memory, leaving only a minimalistic loader on disk that relies on machine-specific data (OctLurk uses the drive serial number, and SilkLurk uses the computer name) to decode payload locations and contents. This victim-specific encoding makes reverse engineering and automated detection considerably harder.”

    Asian central ChineseSpeaking Governments hackers OctLurk SilkLurk Suspected Target
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CareCloud Data Breach Impacts Over 350,000

    EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

    OpenAI says its new GPT 5.6 models are becoming more cost-efficient

    Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

    Copilot worm can spread through Microsoft Word docs

    CISA warns of cyberattacks disrupting U.S. water utilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Amazon is splitting its $600 million tariff refund with customers – here’s who’s eligible

    July 31, 2026

    CareCloud Data Breach Impacts Over 350,000

    July 31, 2026

    Bitcoin (BTC) price’s July gain survives hawkish Fed, AI meltdown and Coldcard fallout

    July 31, 2026

    Indigenous Parakanã fear election U-turn may spark new invasions in Brazil

    July 31, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Amazon is splitting its $600 million tariff refund with customers – here’s who’s eligible

    July 31, 2026

    CareCloud Data Breach Impacts Over 350,000

    July 31, 2026

    Bitcoin (BTC) price’s July gain survives hawkish Fed, AI meltdown and Coldcard fallout

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.