logo

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

ID: 31aa0c33-9485-596f-8012-e80d85311590

STIX ID: report--31aa0c33-9485-596f-8012-e80d85311590

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Saurabh Sharma, Yaroslav Kikel

...
...

This report analyzes two related memory‑focused backdoors (OctLurk and SilkLurk) and a proxy utility (LurkProxy) observed since January 2025 targeting government and critical‑sector organizations in Central Asia and Syria: it documents heavily obfuscated, victim‑specific loaders, network protocols and encryption schemes, a plugin architecture enabling command shells, file management, keylogging, credential harvesting and proxying, outlines post‑compromise activity (Impacket secretsdump, Pandora RC, Fscan, PlugX deployment), provides extensive IoCs (domains, IPs, hashes, file paths) and assesses the operator as a Chinese‑speaking, capable threat actor sharing infrastructure with other campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.