Technology News

Suspected Chinese‑Speaking Threat Actor Targets Central Asian Governments with OctLurk and SilkLurk

A wave of cyber attacks targeting Central Asian governments has been linked to a Chinese‑speaking threat actor. The actor deployed OctLurk and SilkLurk across Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria.

A new wave of cyber attacks targeting government organizations across Central Asia has been linked to a Chinese-speaking threat actor.

Since January 2025, the actor has deployed OctLurk and SilkLurk to infiltrate systems in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.

OctLurk is a remote access trojan that has been observed in the wild for its stealthy persistence and encrypted command-and-control traffic.

SilkLurk is a lateral-movement toolkit that leverages Windows administrative shares and SMB to spread within victim networks.

The attacks have focused on sectors such as healthcare, research, and government offices, all of which contain sensitive data that could support espionage objectives.

Security researchers noted that the actor’s communications are predominantly in Chinese, suggesting either a Chinese-based operator or a Chinese-language persona used to obfuscate attribution.

In a public statement, officials in the affected countries urged organizations to review their network perimeter defenses and monitor for the known indicators of OctLurk and SilkLurk activity.

Both tools exhibit sophisticated evasion tactics, including process injection, DLL sideloading, and the use of legitimate system utilities to hide their presence.

OctLurk’s command-and-control channels are often hosted on domains that use Chinese characters, further complicating detection by conventional DNS filtering.

Defenders are advised to block known C2 domains, enable application whitelisting, and enforce least-privilege access controls to limit lateral movement: block known C2 domains, enable application whitelisting, enforce least-privilege access controls.

Additional recommendations include deploying network segmentation to isolate critical infrastructure and monitoring for anomalous SMB traffic that could signal SilkLurk activity: deploy network segmentation, isolate critical infrastructure, monitor for anomalous SMB traffic.

These findings underscore the growing sophistication of state-backed threat actors and the importance of proactive security measures in Central Asian government networks.

Suspected Chinese‑Speaking Threat Actor Targets Central Asian Governments with OctLurk and SilkLurk

A new wave of cyber attacks targeting government organizations across Ce…

A new wave of cyber attacks targeting government organizations across Ce…

A new wave of cyber attacks targeting government organizations across Central Asia has been linked to a Chinese-speaking threat actor.

Since January 2025, the actor has deployed OctLurk and SilkLurk to infiltrate systems in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.

OctLurk is a remote access trojan that has been observed in the wild for…

OctLurk is a remote access trojan that has been observed in the wild for…

OctLurk is a remote access trojan that has been observed in the wild for its stealthy persistence and encrypted command-and-control traffic.

SilkLurk is a lateral-movement toolkit that leverages Windows administrative shares and SMB to spread within victim networks.

The attacks have focused on sectors such as healthcare, research, and go…

The attacks have focused on sectors such as healthcare, research, and go…

The attacks have focused on sectors such as healthcare, research, and government offices, all of which contain sensitive data that could support espionage objectives.

Security researchers noted that the actor’s communications are predominantly in Chinese, suggesting either a Chinese-based operator or a Chinese-language persona used to obfuscate attribution.

In a public statement, officials in the affected countries urged organiz…

In a public statement, officials in the affected countries urged organiz…

In a public statement, officials in the affected countries urged organizations to review their network perimeter defenses and monitor for the known indicators of OctLurk and SilkLurk activity.

Both tools exhibit sophisticated evasion tactics, including process injection, DLL sideloading, and the use of legitimate system utilities to hide their presence.

OctLurk’s command-and-control channels are often hosted on domains that…

OctLurk’s command-and-control channels are often hosted on domains that…

OctLurk’s command-and-control channels are often hosted on domains that use Chinese characters, further complicating detection by conventional DNS filtering.

Defenders are advised to block known C2 domains, enable application whitelisting, and enforce least-privilege access controls to limit lateral movement: block known C2 domains, enable application whitelisting, enforce least-privilege access controls.

Additional recommendations include deploying network segmentation to iso…

Additional recommendations include deploying network segmentation to iso…

Additional recommendations include deploying network segmentation to isolate critical infrastructure and monitoring for anomalous SMB traffic that could signal SilkLurk activity: deploy network segmentation, isolate critical infrastructure, monitor for anomalous SMB traffic.

These findings underscore the growing sophistication of state-backed threat actors and the importance of proactive security measures in Central Asian government networks.