RECENT discoveries by Kaspersky's GReAT team have unveiled two undocumented backdoors, OctLurk and SilkLurk, targeting government organizations in Central Asia, including Afghanistan and Kazakhstan. These backdoors utilize admin credentials for infection, employing complex methods for encryption tied to the victim's machine. Both backdoors facilitate extensive espionage activities such as file management, screen capture, and credential theft.
Kaspersky attributes these operations to a Chinese-speaking actor, although precise attribution remains unconfirmed. The campaign highlights vulnerabilities in sensitive sectors like foreign affairs and law enforcement, emphasizing the need for enhanced cybersecurity measures.