discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

By Ravie Lakshmanan·Jul 31·thehackernews.com·2 min read

Intelligence analysis by Llama

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
Image: thehackernews.com

Kaspersky researchers have identified a new obfuscated backdoor, OctLurk, and a specialized utility, LurkProxy, used in the attacks, which can download and inject additional plugins to perform further malicious actions.

Why it matters

The attacks highlight the continuous refinement of tactics by threat actors to evade detection and maintain control over compromised networks, posing a significant threat to government organizations and their sensitive information.

Imagine a group of hackers who are very good at hiding their tracks. They use special tools to sneak into computers and steal important information. They can even control the computer remotely, like a remote control. This is a big problem because it can affect many people and organizations.

Analysis

A Sophisticated Threat Actor Emerges

The recent wave of cyber attacks targeting government organizations in Central Asia has been linked to a Chinese-speaking threat actor. The attacks, which began in January 2025, have been characterized by the use of two new obfuscated backdoors, OctLurk and SilkLurk, as well as a specialized utility, LurkProxy, to proxy network traffic.

The Tools of the Trade

OctLurk and SilkLurk are designed to operate primarily in memory, leaving only a minimalistic loader on disk. This makes reverse engineering and automated detection considerably harder. The backdoors can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access.

The Attack Chain

The initial access vector used in these attacks is currently unknown. However, Kaspersky analysis has found that OctLurk is injected into memory and deployed by means of a loader, with the attackers also checking internet connectivity to the domain "dns.ssentialserv[.]xyz" before executing a batch script responsible for launching LurkProxy. The tool then establishes contact with a remote server ("154.196.162[.]76") for command-and-control (C2).

The Impact

The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks. The attacks have been linked to a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall), indicating shared infrastructure across multiple OS-targeting campaigns.

Conclusion

The recent wave of cyber attacks targeting government organizations in Central Asia serves as a reminder of the ongoing threat posed by sophisticated threat actors. The use of advanced malware tools, such as OctLurk and SilkLurk, highlights the need for continued vigilance and the development of effective countermeasures to mitigate the impact of these attacks.

Key points

  • A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia.
  • The attacks have been linked to the use of two new obfuscated backdoors, OctLurk and SilkLurk, as well as a specialized utility, LurkProxy.
  • The backdoors can download and inject additional plugins to perform further malicious actions, including launching command shells and performing file system activity.
  • The initial access vector used in these attacks is currently unknown.
  • The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks.
The Upside

If the development of these advanced malware tools is addressed, it could lead to the creation of more effective countermeasures to mitigate the impact of these attacks. This could result in a safer and more secure online environment for all users.

The Downside

The emergence of these advanced malware tools could lead to a significant increase in the number of successful cyber attacks, resulting in the theft of sensitive information and the compromise of critical infrastructure.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsmalwarethreat-intelligencegovernment-securitycredential-theftdata-theftendpoint-securitynetwork-securityremote-access

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 31, 2026

Source

thehackernews.com

Share

Topics

malwarethreat-intelligencegovernment-securitycredential-theftdata-theftendpoint-securitynetwork-securityremote-access

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.