OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
ID: 04f2c1e6-0548-5461-acb4-50264b198116
STIX ID: report--04f2c1e6-0548-5461-acb4-50264b198116
Feed Name: HackRead
Kaspersky reported two novel Windows backdoors — OctLurk and SilkLurk — plus a relay implant (LurkProxy) used since January 2025 in targeted cyber-espionage against government, public institutions and critical infrastructure across several Central Asian countries and Syria; infections are highly tailored to individual machines (USB/C-drive serial and hostname-derived keys), use service/task persistence and DLL side-loading, operate largely in memory, and enable credential theft, keylogging, remote control and lateral discovery, with evidence linking infrastructure to an earlier Linux campaign and occasional deployment of PlugX as a second-stage payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
