All incidents

OctLurk and SilkLurk backdoors target Central Asian government agencies

malwareopenJul 30, 2026 — Aug 5, 2026
OctLurk and SilkLurk backdoors target Central Asian government agencies

KASPERSKY’S GReAT team has uncovered two previously undocumented backdoors, OctLurk and SilkLurk, that are being used to spy on government organisations across Central Asia. The malware was first observed in late July 2026 and remained active through early August, hitting entities in Afghanistan, Kazakhstan and neighbouring states. The campaign focuses on stealing credentials, capturing screenshots and exfiltrating files from compromised systems.

Both OctLurk and SilkLurk gain initial access by abusing valid administrator credentials, a technique that lets them bypass many perimeter defences. Once inside they deploy heavily obfuscated loaders that decrypt and execute payloads uniquely tailored to each victim’s machine. The loaders then inject additional plugins that enable a wide range of malicious actions, including file enumeration, screen capture, network scanning and remote command execution.

The backdoors use encryption keys derived from specific system attributes, which means the same payload will not run on a different host without the correct key. This victim‑specific approach complicates detection by traditional signature‑based tools. Kaspersky analysts note that the code contains strings consistent with a Chinese‑speaking developer, although they have not linked the activity to any known threat group. No CVEs have been assigned to the vulnerabilities exploited by these tools.

Intrusion attempts were recorded between 30 July and 5 August 2026, with victims spanning foreign affairs ministries, law‑enforcement agencies, healthcare providers and logistics companies. The focus on sectors that handle sensitive diplomatic and operational information suggests the attackers are pursuing intelligence rather than financial gain. The activity underscores the persistence of credential‑based intrusion methods in high‑value targets.

Defenders should begin by reviewing privileged account logs for unusual authentication patterns, especially logins from unfamiliar locations or at odd hours. Enforcing multi‑factor authentication on all administrative accounts and limiting the reuse of credentials across systems can reduce the initial foothold. Endpoint protection platforms should be updated to recognise the obfuscated loader characteristics described in the public reports.

Network segmentation is also critical; separating sensitive administrative zones from user‑facing segments limits lateral movement even if credentials are compromised. Regular credential rotation, combined with least‑privilege enforcement, helps minimise the window of abuse. Finally, sharing indicators of compromise with trusted partners and subscribing to threat‑intelligence feeds that include the OctLurk and SilkLurk signatures will improve the chances of early detection.

Intelligence briefing updated Aug 5, 2026

Root sourcesecurelist.com
Timeline Coverage

Swipe to explore timeline