Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk 8%

By Ravie Lakshmanan18%

7/31/2026, 11:52:04 AM

BS Summary: This article contains 12 faulty reasoning types, including Negativity Bias, Overconfidence Bias, and Ambiguity (Equivocation), with Appeal to Authority as the most egregious example at 20.1% saturation with 145 hits. Analysis detected 689 faulty-reasoning hits from 723 analyzed words, generating a BS Score of 19.4% and a BS Rank of 8% (23,696 of 25,563 articles). This article is better (less manipulative) than 92.70% of the article peer group.

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. 
These targeted organizations operate across several sectors, such as healthcare, research, government offices, ministries of foreign affairs, logistics, law-enforcement agencies, urban planning and facilities management, and public educational establishments, per Kaspersky. 
The activity has not been linked to any known adversary or group. 
The attacks are characterized by the use of two new obfuscated backdoors the Russian cybersecurity company is tracking as OctLurk and SilkLurk, as well as a specialized utility codenamed LurkProxy to proxy network traffic. 
"OctLurk and SilkLurk can download and inject additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access," researchers Saurabh Sharma and Yaroslav Kikel said. 
Once run, OctoLurk first collects system information, encrypts it, and sends it to a hard-coded C2 server ("dns.multitoconference[.]com") over a stream socket connection. 
It's equipped to load plugins received from the server directly into memory to enable command execution, file operations, clipboard content gathering and modification, screenshot capture, and mouse movements. 
The threat actors have been found to leverage the backdoor's command shell plugin to perform the following series of actions - 
Fingerprint the host and harvest extensive data about the compromised system. 
Run commands to export successful logon events for remote interactive logons and to query those events for specific users. 
Harvest password hashes from domain controllers using Impacket's "secretsdump.py" tool. 
Drop and execute a keylogger that masquerades as AnyDesk to sidestep detection. 
Decrypt and extract passwords from Google Chrome and Mozilla Firefox. 
Establish remote access to the victim machine using Pandora RC agent. 
Scan internal and public networks using Fscan to identify services running on specific ports, such as Secure Shell (SSH) on port 22 and MySQL on port 3306, and then attempt to access these services using credentials from a password file named "pp.txt." 
Connect to an email server, authenticate with a username and password, and issue commands to collect or manipulate emails. 
LurkProxy, for its part, can function as a reverse proxy in two distinct modes, either as a SOCKS5 proxy or a transparent proxy. 
At any given time, the malware can operate in only one mode to route network traffic through a target address. 
The third tool in the threat actor's arsenal is SilkLurk, which is launched by means of a DLL that, in turn, is executed using a DLL side-loading sequence. 
The backdoor then creates a TCP socket and connects to a C2 server specified in its configuration, followed by collecting victim information and transmitting it to the server. 
In response, the server sends a command that's to be executed on the infected endpoint. 
This can involve getting the system's local time, setting a sleep interval that determines the frequency at which the backdoor polls the C2 server, sending or updating backdoor configuration, and receiving and injecting additional plugins into memory. 
The post-compromise activity linked to SilkLurk is below - 
Invoke "cmd.exe" to launch PowerShell and run commands to connect to shared network resources with administrative credentials, search and stage confidential documents, disconnect from the network shares, and use legitimate archiving tools like WinRAR and 7-Zip to archive the stolen data. 
Run "cmd.exe" to initiate a DLL side-loading chain to drop PlugX, a known backdoor used by Chinese hacking groups. 
Kaspersky said it found infrastructure overlaps between the campaign and a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall). 
"This overlap points to shared infrastructure across multiple OS-targeting campaigns, though it remains unclear whether these activities ran concurrently or at different times," Kaspersky said. 
"The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks." 
"Both families operate primarily in memory, leaving only a minimalistic loader on disk that relies on machine-specific data (OctLurk uses the drive serial number, and SilkLurk uses the computer name) to decode payload locations and contents. 
This victim-specific encoding makes reverse engineering and automated detection considerably harder." 
Confirmation Bias
3.7%
Anchoring Bias
0%
Availability Heuristic
6.6%
Representativeness Heuristic
0%
Hindsight Bias
0%
Overconfidence Bias
13.7%
Framing Effect
1.5%
Loss Aversion
0%
Status Quo Bias
0%
Sunk Cost Effect
0%
Optimism Bias
0%
Pessimism Bias
0%
Negativity Bias
14%
Self-Serving Bias
0%
Fundamental Attribution Error
0%
Actor-Observer Bias
0%
In-Group Bias
0%
Out-Group Homogeneity Bias
5.1%
Halo Effect
0%
Horn Effect
0%
Dunning-Kruger Effect
0%
Recency Bias
0%
Primacy Effect
1.5%
Blind-Spot Bias
0%
Ad Hominem
0%
Straw Man
0%
Appeal to Authority
20.1%
False Dilemma
0%
Slippery Slope
0%
Circular Reasoning
0%
Hasty Generalization
3.7%
Red Herring
0%
Bandwagon
0%
Appeal to Emotion
0%
Begging the Question
0%
Post Hoc (False Cause)
0%
Tu Quoque
0%
Burden of Proof
5.1%
Appeal to Nature
0%
Composition/Division
0%
Anecdotal
0%
No True Scotsman
0%
Ambiguity (Equivocation)
13.6%
Gambler’s Fallacy
0%
Middle Ground
0%
Personal Incredulity
0%
Special Pleading
0%
Genetic Fallacy
0%
Unattributed Quote
6.6%
Quote-first Misdirection
0%
Biased Writer Voice
0%
Indoctrination
0%
Politically Left Leaning Bias
0%
Politically Right Leaning Bias
0%
Attempt to Sell a Product or Service
0%

723 words analyzed.

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.