HackMyIP
← Back to News
2026-07-31 The Hacker News

Chinese-Speaking Hackers Hit Central Asia With OctLurk and SilkLurk Backdoors

APTMalwareThreat Intel

A Chinese-speaking threat actor has been linked to a sustained cyber espionage campaign targeting government organizations across Central Asia, including entities in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, ongoing since January 2025. Kaspersky researchers Saurabh Sharma and Yaroslav Kikel report that the victims span healthcare, research, ministries of foreign affairs, logistics, law-enforcement agencies, urban planning departments, and public educational institutions. The activity has not been attributed to any previously tracked adversary, marking it as a distinct operation within the regional threat landscape.

The campaign relies on two newly discovered obfuscated backdoors, OctLurk and SilkLurk, alongside a proxy utility named LurkProxy used to tunnel network traffic. OctLurk is loaded into memory by a loader that first checks connectivity to the domain dns.ssentialserv[.]xyz before executing a batch script to launch LurkProxy, which then beacons to the C2 server at 154.196.162[.]76. Once active, the backdoor collects host information, encrypts it, and exfiltrates it to dns.multitoconference[.]com over a stream socket. Operators use the backdoor's plugin architecture to inject additional modules for command shell execution, file system manipulation, clipboard capture, screenshotting, credential dumping, keylogging, browser password theft, and remote access. Defenders investigating such infrastructure can use a WHOIS lookup to trace ownership of suspicious domains and IPs, or run a DNS leak test to verify whether their own resolvers are exposing queries to adversary monitoring.

Operators behind the campaign leverage the command shell plugin to fingerprint compromised hosts, export successful remote interactive logon events, dump password hashes from domain controllers via Impacket's secretsdump.py, and deploy a keylogger disguised as the legitimate AnyDesk remote-access tool to evade detection. They extract saved credentials from Google Chrome and Mozilla Firefox, establish persistent remote access through a Pandora RC agent, and run Fscan to enumerate SSH (port 22) and MySQL (port 3306) services across internal and public networks before attempting credential-based access. Network defenders can audit their own exposure with a port scanner to verify which services are reachable from the internet, and employees should run a password checker to confirm whether credentials stored in their browsers have been compromised in known breaches. Investigators can also test outbound traffic against a VPN and proxy detector to identify whether attacker staging infrastructure is masquerading as residential or anonymous traffic.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →