OctLurk and SilkLurk Backdoors Target Central Asia

Payroll Pirate AiTM phishing diagram showing session hijacking and payroll redirect attack flow bank phishing reimbursement Nova ransomware apology StablR stablecoin depeg hack

The system drive serial number or computer name magically transformed into an indispensable key. Without it, the malicious program simply refused to decrypt its own payload. Recently, Kaspersky researchers uncovered two previously undocumented, highly modular programs: OctLurk and SilkLurk. Attackers deployed these sophisticated backdoors in targeted cyber espionage campaigns against government and state-affiliated organizations throughout Central Asia and Syria. According to the technical report, this prolonged campaign has been actively running since at least January 2025.

Investigators discovered extensive infection traces spanning Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. Furthermore, the extensive list of victims encompasses healthcare institutions, research centers, and government agencies. It also includes foreign ministries, law enforcement organizations, logistics companies, urban planning entities, and public educational institutions.

Attributing the Intricate Cyber Espionage Campaign

With a moderate degree of confidence, security specialists attribute both OctLurk and SilkLurk to a single, Chinese-speaking threat actor. However, they have not yet successfully linked this campaign to a previously known advanced persistent threat (APT) group. This attribution relies upon several compelling factors. First, both backdoors frequently co-exist on compromised machines. Second, they share identical working directories. Finally, researchers documented a specific incident where attackers deployed SilkLurk directly through the OctLurk command shell.

Advanced Evasion: Environmental Keying and Obfuscation

The developers meticulously crafted the OctLurk and SilkLurk loaders specifically for each targeted victim. OctLurk dynamically generated its decryption key using the unique C: drive serial number. Conversely, SilkLurk calculated a precise 32-bit hash derived directly from the infected computer’s name. The malware utilized these calculated values to decrypt both the filepath to the payload and the malicious code itself. Consequently, if researchers transferred a copied loader to a pristine analytical machine, it would inevitably fail to execute or reveal its core module.

Furthermore, the malware authors severely complicated forensic analysis through heavily obfuscated code, zlib compression, and double XOR encryption schemes. They also implemented multiple layers of arithmetic and logical operations. Crucially, the primary backdoors and supplementary plugins operated almost exclusively within the system’s random access memory (RAM). Only a minuscule loader remained persistently on the hard drive. Operating entirely in memory drastically reduced the creation of conspicuous files, thereby frustrating automated sandboxes attempting to replicate the infection cycle.

The OctLurk Infection Vector and Command Hierarchy

To successfully install OctLurk, the attackers leveraged compromised administrative credentials. Next, they created a scheduled task deceptively named “GoogleUpDate” on the remote computers. This task executed a batch script holding elevated System account privileges. Subsequently, the script registered a new Windows service and loaded the malicious dynamic-link library (DLL). Finally, the loader decrypted the payload, injected the primary backdoor into memory, and established communication with the command-and-control (C2) server over port 443.

Once active, OctLurk meticulously transmitted detailed system information. It reported the operating system version, computer name, current user, local hostname, IP address, and precise system time. Before transmission, the malware compressed this intelligence using zlib and encrypted it twice utilizing XOR. Notably, one encryption key consisted of 83 entirely random bytes. Upon receiving this data, the C2 server could dispatch new commands or supplementary plugins.

Researchers deeply analyzed specific modules designed to launch command shells, manipulate files, and remotely control the compromised machine. Consequently, the operators gained unfettered ability to search, read, create, copy, move, rename, and delete sensitive files. Furthermore, they could effortlessly alter timestamps, execute arbitrary programs, capture screenshots, and manipulate the system clipboard. They even possessed the capability to move the mouse pointer and simulate keystrokes remotely.

Post-Exploitation Tactics and Lateral Movement

After firmly establishing persistence, the attackers conducted exhaustive reconnaissance of the infected systems. Specialized batch scripts harvested intelligence concerning installed hardware, software, active user sessions, and running processes. They also gathered network configurations, installed antivirus solutions, Microsoft Defender settings, open ports, DNS caches, startup items, and scheduled tasks. Specific commands targeted and extracted successful remote login logs, including sensitive RDP connections.

For extensive credential theft, the operators deployed a compiled executable version of Impacket’s secretsdump. This tool efficiently extracted password hashes directly from domain controllers. After successfully exfiltrating the hashes, the attackers queried the Domain Controllers group membership. This action likely aimed to identify additional targets for deeper lateral movement across the network.

Simultaneously, a dedicated keylogger secretly recorded keystrokes and clipboard contents into two separate files. Before saving the data, the keylogger modified each individual byte to evade simple detection. Another independent utility specifically extracted saved passwords from Chrome and Firefox browsers. Finally, the operators installed Pandora RC, a known remote access trojan, for redundant control.

For internal network reconnaissance, the attackers utilized Fscan. This scanner aggressively hunted for accessible hosts, known vulnerabilities, and active network services, specifically targeting SSH on port 22 and MySQL on port 3306. Following discovery, it attempted authentication using credentials compiled in a pre-configured file. Furthermore, the operators employed the curl command to connect directly with internal mail servers, verify stolen credentials, and selectively access specific email inboxes.

LurkProxy: Securing the Command Channel

Alongside OctLurk, the operators frequently deployed LurkProxy. This specialized utility utilized a nearly identical architecture but functioned exclusively as a reverse proxy server rather than a backdoor. LurkProxy silently monitored port 64980 across all available network interfaces. It established a highly secure TLS connection with the C2 server, transmitting packets utilizing a custom binary protocol protected by zlib compression and double XOR encryption.

LurkProxy seamlessly supported two distinct operational modes. The first mode effectively transformed the infected computer into a SOCKS5 proxy, allowing attackers to route bidirectional traffic toward selected targets through the victim’s own infrastructure. The second mode operated as a transparent proxy connecting to a predetermined IP address and port. In the specific sample analyzed by researchers, the operators had actively enabled the SOCKS5 capability.

SilkLurk and the Deployment of PlugX

SilkLurk achieved persistence through a distinct methodology. The attackers covertly registered new services that ostensibly launched legitimate NVIDIA and Realtek executables. However, they maliciously positioned compromised DLLs alongside these trusted programs. Consequently, the legitimate applications inadvertently loaded the substituted components via a technique known as DLL side-loading. The malicious loader then verified the executing process, transferred the encrypted payload file to a designated directory, and created an “RmSs” service configured for automatic startup and failure recovery. Ultimately, it decrypted and injected the SilkLurk backdoor directly into memory.

A SilkLurk configuration block could harbor up to four distinct C2 servers and parameters for two proxies. Upon successful connection, the backdoor transmitted the computer name, DNS domain, username, CPU architecture, Windows version, IP address, process ID, system uptime, and the specific malicious module name. The operators possessed the authority to query the local time, adjust reconnection delays, update configurations, load extra modules into memory, and execute plugin functions.

During one observed intrusion, SilkLurk initiated a command shell and launched PowerShell. The attackers rapidly connected to shared network drives utilizing compromised administrative credentials. They scoured the shares for highly confidential documents. Upon completing their search, they meticulously disconnected the network resources to obscure their tracks. They subsequently packaged the stolen files using legitimate, unmodified copies of WinRAR and 7-Zip.

Remarkably, the operators also installed the notorious PlugX malware via SilkLurk. A separate deployment file unpacked a legitimate Symantec executable, a malicious loader, and an encrypted payload. PlugX covertly injected itself into the legitimate svchost.exe process, established persistence as the “SymantecRAS” service, and utilized the specific campaign identifier “KG_MFA.”

OctLurk and SilkLurk backdoors cyber espionage operation map

Infrastructure Overlap and Final Conclusions

The command domains for both SilkLurk and PlugX resolved to the exact same zone: kozow.com. The modular PlugX remote access trojan has been actively utilized since at least 2008 and boasts deep historical ties to Chinese-speaking threat actors. This infrastructure overlap, combined with the deployment of PlugX, provided critical supplementary grounds for the campaign’s preliminary attribution.

The attackers constructed the underlying infrastructure for OctLurk, SilkLurk, and LurkProxy using virtual private servers. A portion of the IP addresses associated with OctLurk and LurkProxy directly overlapped with the infrastructure utilized in a separate campaign targeting critical facilities in Kazakhstan, which was previously detailed in a GTS presentation.

Earlier, in March 2025, attackers deployed a Linux backdoor named TrustFall (also known as MystRodX and SilentRaid). In October 2025, GTS researchers discovered novel samples and additional C2 servers. Crucially, OctLurk and LurkProxy subsequently utilized three of these identical IP addresses.

This distinct infrastructure overlap strongly indicates a connection between multiple campaigns targeting both Windows and Linux environments. However, it does not definitively prove simultaneous operation or unified centralized command. The report explicitly omits the initial access vector used to penetrate these organizations. Nevertheless, the observed post-exploitation activity clearly demonstrates a highly calculated strategy. After securing administrative privileges, the operators established multiple, independent command channels. They aggressively harvested credentials and deployed redundant remote access tools. This ensured they maintained persistent access even if defenders detected and neutralized one of the components.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply