Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.
Intelligence analysis by Llama

Kaspersky researchers have identified a new obfuscated backdoor, OctLurk, and a specialized utility, LurkProxy, used in the attacks, which can download and inject additional plugins to perform further malicious actions.
Imagine a group of hackers who are very good at hiding their tracks. They use special tools to sneak into computers and steal important information. They can even control the computer remotely, like a remote control. This is a big problem because it can affect many people and organizations.
Analysis
A Sophisticated Threat Actor Emerges
The recent wave of cyber attacks targeting government organizations in Central Asia has been linked to a Chinese-speaking threat actor. The attacks, which began in January 2025, have been characterized by the use of two new obfuscated backdoors, OctLurk and SilkLurk, as well as a specialized utility, LurkProxy, to proxy network traffic.
The Tools of the Trade
OctLurk and SilkLurk are designed to operate primarily in memory, leaving only a minimalistic loader on disk. This makes reverse engineering and automated detection considerably harder. The backdoors can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access.
The Attack Chain
The initial access vector used in these attacks is currently unknown. However, Kaspersky analysis has found that OctLurk is injected into memory and deployed by means of a loader, with the attackers also checking internet connectivity to the domain "dns.ssentialserv[.]xyz" before executing a batch script responsible for launching LurkProxy. The tool then establishes contact with a remote server ("154.196.162[.]76") for command-and-control (C2).
The Impact
The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks. The attacks have been linked to a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall), indicating shared infrastructure across multiple OS-targeting campaigns.
Conclusion
The recent wave of cyber attacks targeting government organizations in Central Asia serves as a reminder of the ongoing threat posed by sophisticated threat actors. The use of advanced malware tools, such as OctLurk and SilkLurk, highlights the need for continued vigilance and the development of effective countermeasures to mitigate the impact of these attacks.
Key points
- A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia.
- The attacks have been linked to the use of two new obfuscated backdoors, OctLurk and SilkLurk, as well as a specialized utility, LurkProxy.
- The backdoors can download and inject additional plugins to perform further malicious actions, including launching command shells and performing file system activity.
- The initial access vector used in these attacks is currently unknown.
- The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks.
If the development of these advanced malware tools is addressed, it could lead to the creation of more effective countermeasures to mitigate the impact of these attacks. This could result in a safer and more secure online environment for all users.
The emergence of these advanced malware tools could lead to a significant increase in the number of successful cyber attacks, resulting in the theft of sensitive information and the compromise of critical infrastructure.


