THE content discusses the emergence of two new backdoors, OctLurk and SilkLurk, targeting government organizations in Central Asia. These backdoors primarily focus on espionage activities, and the victims include institutions from various sectors such as healthcare and logistics. Both backdoors utilize heavily obfuscated loaders, allowing them to decrypt and execute payloads specific to each victim's machine.
Key functionalities include downloading and injecting plugins for various malicious tasks, credential harvesting, network scans, and remote access. The report suggests a single threat actor operates both backdoors, likely a Chinese-speaking group, though attribution to a specific known group isn't established. Their techniques involve sophisticated deception methods to maintain control and evade detection, underscoring a trend in modern cyber-espionage.