logo

OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries

ID: 04f2c1e6-0548-5461-acb4-50264b198116

STIX ID: report--04f2c1e6-0548-5461-acb4-50264b198116

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Waqas

...
...

Kaspersky reported two novel Windows backdoors — OctLurk and SilkLurk — plus a relay implant (LurkProxy) used since January 2025 in targeted cyber-espionage against government, public institutions and critical infrastructure across several Central Asian countries and Syria; infections are highly tailored to individual machines (USB/C-drive serial and hostname-derived keys), use service/task persistence and DLL side-loading, operate largely in memory, and enable credential theft, keylogging, remote control and lateral discovery, with evidence linking infrastructure to an earlier Linux campaign and occasional deployment of PlugX as a second-stage payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.