OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
ID: 31aa0c33-9485-596f-8012-e80d85311590
STIX ID: report--31aa0c33-9485-596f-8012-e80d85311590
Feed Name: Securelist by Kaspersky
This report analyzes two related memory‑focused backdoors (OctLurk and SilkLurk) and a proxy utility (LurkProxy) observed since January 2025 targeting government and critical‑sector organizations in Central Asia and Syria: it documents heavily obfuscated, victim‑specific loaders, network protocols and encryption schemes, a plugin architecture enabling command shells, file management, keylogging, credential harvesting and proxying, outlines post‑compromise activity (Impacket secretsdump, Pandora RC, Fscan, PlugX deployment), provides extensive IoCs (domains, IPs, hashes, file paths) and assesses the operator as a Chinese‑speaking, capable threat actor sharing infrastructure with other campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
