OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
OctLurk and SilkLurk backdoors target governments in 6 countries, stealing sensitive data.
Summary
Kaspersky has identified two new Windows backdoors, OctLurk and SilkLurk, used in cyberespionage attacks against government organizations in six Central Asian and Middle Eastern countries since January 2025. These backdoors are designed to be highly specific to each victim and can steal passwords, emails, and files, with attackers deploying additional tools like Impacket and PlugX. The campaign shows evidence of shared command infrastructure with a previous Linux malware campaign, suggesting a potential link to a Chinese-speaking threat actor.
Full text
Security Cyber Attacks MalwareOctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. byWaqasAugust 5, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Kaspersky has identified two previously undocumented Windows backdoors in a cyber-espionage campaign targeting government organizations and public institutions in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and the Syrian Arab Republic since January 2025. The company named the malware OctLurk and SilkLurk. According to Kaspersky’s report, the affected organizations include healthcare and research bodies, government offices, foreign ministries, logistics providers, law-enforcement agencies, urban planning departments, facilities managers and public educational institutions. Researchers note that each infection is prepared for a particular computer. OctLurk derives part of its decryption key from the serial number of the C drive, while SilkLurk computes a hash from the computer name. Those values unlock the payload path and malicious code, making each loader specific to its intended victim. On infected computers, OctLurk is installed through scheduled tasks and malicious Windows services after the attacker obtains administrative credentials. SilkLurk uses legitimate NVIDIA and Realtek programs to side-load malicious DLLs, then creates a service that restarts after a failure. Both backdoors place their main components into memory while leaving a small loader on disk. After connecting to command servers, OctLurk and SilkLurk can receive and inject additional plugins into memory. These components give the operator command-shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access. During OctLurk infections, Kaspersky observed the attackers collecting system and network details before deploying tools such as Impacket’s secretsdump, a keylogger, a browser password extractor and the Fscan network scanner. They also installed Pandora remote-control agents and connected directly to email servers using account credentials. SilkLurk was used to open PowerShell, connect to shared network resources with administrative credentials and search for confidential documents. The attackers compressed collected material with WinRAR or 7-Zip, disconnected from network shares to hide which internal servers had been accessed, and installed the PlugX remote-access malware as a second-stage payload. Alongside the two backdoors, the attackers deployed LurkProxy, a separate implant built with a design similar to OctLurk. Kaspersky said LurkProxy is not a backdoor. Its main role is to relay network traffic through a TLS-encrypted connection, operating as either a SOCKS5 or transparent reverse proxy. Kaspersky’s technical report, published on July 30, 2026, also connected part of the command infrastructure to a March 2025 campaign targeting critical infrastructure in Kazakhstan with Linux malware known as TrustFall, MystRodX or SilentRaid. Researchers also found that three command-server addresses from that campaign were used by OctLurk and LurkProxy, although Kaspersky could not determine whether the operations ran at the same time. Evidence of common control appeared on the infected systems themselves. Some victims had both backdoors; the malware sometimes used the same staging directories, and Kaspersky saw an OctLurk command shell deliver a SilkLurk loader. Kaspersky assesses with medium confidence that a Chinese-speaking actor operates both backdoors. The use of PlugX, which has a long history among Chinese-speaking groups, supports that assessment, but researchers have not attributed the campaign to any known threat group. Kaspersky published file hashes, domains, IP addresses, and file paths that organizations can use to search for related activity. Additional indicators are available to subscribers of its threat intelligence service. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts AfghanistanbackdoorCentral AsiaChinaKasperskyLinuxLurkProxyMalwareMystRodXOctLurkPlugXSilentRaidSilkLurkSyriaTrustFallWindowsWinRAR Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Big Data Requires New Approaches to Cybersecurity By 2023, the volume of data generated worldwide had reached 120 zettabytes, and information flows continue to grow… byLyudmila Chicherova Read More Security Sound Waves can Help Hackers Disrupt Functions of Hard Disk Drives Hard Disk Drives (HDDs) are most commonly used storage components because these tend to be energy efficient and… byWaqas Read More Security Cybersecurity Has Never Been More Unstable Than It Is Now The world of cybersecurity is nearing a point of no return, with the number of data breaches, password… byOwais Sultan Read More Security Apple News 15-year-old Unpatched Root Access Bug found in Apple’s macOS An IT security researcher has leaked details on an unpatched Apple’s macOS bug which lets attackers gain root… byWaqas
Indicators of Compromise
- malware — OctLurk
- malware — SilkLurk
- malware — LurkProxy
- malware — TrustFall
- malware — MystRodX
- malware — SilentRaid
- malware — PlugX