discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

By Ravie Lakshmanan·Jul 31·thehackernews.com·2 min read

Intelligence analysis by Llama

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
Image: thehackernews.com

Kaspersky researchers have identified a new obfuscated backdoor, OctLurk, and a specialized utility, LurkProxy, used in the attacks, which can download and inject additional plugins to perform further malicious actions.

Why it matters

The attacks highlight the continuous refinement of tactics by threat actors to evade detection and maintain control over compromised networks, posing a significant threat to government organizations and their sensitive information.

Imagine a group of hackers who are very good at hiding their tracks. They use special tools to sneak into computers and steal important information. They can even control the computer remotely, like a remote control. This is a big problem because it can affect many people and organizations.

Analysis

A Sophisticated Threat Actor Emerges

The recent wave of cyber attacks targeting government organizations in Central Asia has been linked to a Chinese-speaking threat actor. The attacks, which began in January 2025, have been characterized by the use of two new obfuscated backdoors, OctLurk and SilkLurk, as well as a specialized utility, LurkProxy, to proxy network traffic.

The Tools of the Trade

OctLurk and SilkLurk are designed to operate primarily in memory, leaving only a minimalistic loader on disk. This makes reverse engineering and automated detection considerably harder. The backdoors can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access.

The Attack Chain

The initial access vector used in these attacks is currently unknown. However, Kaspersky analysis has found that OctLurk is injected into memory and deployed by means of a loader, with the attackers also checking internet connectivity to the domain "dns.ssentialserv[.]xyz" before executing a batch script responsible for launching LurkProxy. The tool then establishes contact with a remote server ("154.196.162[.]76") for command-and-control (C2).

The Impact

The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks. The attacks have been linked to a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall), indicating shared infrastructure across multiple OS-targeting campaigns.

Conclusion

The recent wave of cyber attacks targeting government organizations in Central Asia serves as a reminder of the ongoing threat posed by sophisticated threat actors. The use of advanced malware tools, such as OctLurk and SilkLurk, highlights the need for continued vigilance and the development of effective countermeasures to mitigate the impact of these attacks.

Key points

  • A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia.
  • The attacks have been linked to the use of two new obfuscated backdoors, OctLurk and SilkLurk, as well as a specialized utility, LurkProxy.
  • The backdoors can download and inject additional plugins to perform further malicious actions, including launching command shells and performing file system activity.
  • The initial access vector used in these attacks is currently unknown.
  • The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks.
The Upside

If the development of these advanced malware tools is addressed, it could lead to the creation of more effective countermeasures to mitigate the impact of these attacks. This could result in a safer and more secure online environment for all users.

The Downside

The emergence of these advanced malware tools could lead to a significant increase in the number of successful cyber attacks, resulting in the theft of sensitive information and the compromise of critical infrastructure.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsmalwarethreat-intelligencegovernment-securitycredential-theftdata-theftendpoint-securitynetwork-securityremote-access

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 31, 2026

Source

thehackernews.com

Share

Topics

malwarethreat-intelligencegovernment-securitycredential-theftdata-theftendpoint-securitynetwork-securityremote-access

Related

More from this desk

Jul 31·bleepingcomputer.com

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker.

Jul 31·schneier.com

Friday Squid Blogging: Squid Helps Discover New Marine Species

A scientific expedition using a new machine called the Squid discovered thirty-one new marine species in two weeks. The Squid uses lasers to scan microscopic details of how organisms are put together.

Jul 31·bleepingcomputer.com

OpenAI says its new GPT 5.6 models are becoming more cost-efficient

OpenAI has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20%. The new prices affect how it counts usage in Codex and ChatGPT Work.

Jul 31·bleepingcomputer.com

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement.