Intelligence
highCampaignActive

Suspected Chinese-speaking activity targets Central Asian governments with OctLurk and SilkLurk

Kaspersky researchers reported suspected Chinese-speaking activity targeting government and other organisations, mainly in Central Asia, with OctLurk, SilkLurk and LurkProxy. The activity has not been linked to a known threat group.

S
Sebastion

Affected

Central Asian government organisationsAfghan governmentKyrgyz governmentTajik governmentUzbek governmentKazakh governmentSyrian government

Kaspersky researchers Saurabh Sharma and Yaroslav Kikel reported on Securelist that a suspected Chinese-speaking threat actor has targeted organisations mainly in Central Asia since January 2025. Victims were observed in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria across government, healthcare, research, logistics, law enforcement, urban planning and education. The activity has not been linked to any known adversary or group.

The activity uses two newly identified, obfuscated backdoors tracked as OctLurk and SilkLurk. Both can receive and inject plugins in memory for functions including command execution, file activity, credential theft, keylogging, network scanning and remote access. The initial access vector remains unknown.

Kaspersky also identified LurkProxy, a specialised reverse-proxy utility capable of operating as either a SOCKS5 or transparent proxy. Post-compromise observations included password-hash collection, browser password theft, internal network scanning, email access, document staging and deployment of additional remote-access tooling.

Infrastructure used in the activity overlaps with infrastructure previously associated with the C++ implant SilentRaid, also known as MystRodX and TrustFall. Kaspersky presented this overlap as an attribution breadcrumb indicating shared infrastructure across campaigns targeting different operating systems; it remains unclear whether the activities occurred concurrently or at different times. It does not establish attribution to a known APT or demonstrate multiple coordinated teams.

Defenders should use Kaspersky's Securelist research and published indicators to hunt for OctLurk, SilkLurk and LurkProxy activity, while treating the suspected Chinese-speaking assessment and infrastructure overlap with appropriate caution.