Kaspersky Uncovers OctLurk and SilkLurk: Stealth Cyber Espionage Across Central Asia

Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered an ongoing, highly targeted cyber espionage campaign directed at government ministries, healthcare institutions, research centres, and law enforcement agencies across Central Asia and Syria.
Active since January 2025, the operational campaign stands out for its deliberate avoidance of mass distribution. Instead of using generic malware builds, the threat actors deploy customised backdoors namedOctLurk and SilkLurk.
These implants use machine-bound decryption keys to ensure payloads execute exclusively on the intended target's physical hardware, rendering automated security sandboxes and signature-based detection mechanisms ineffective.
Bypassing Automated Sandboxes via Machine Fingerprinting
Traditional security tools evaluate suspicious executables by running them inside isolated sandbox environments to analyse runtime behaviour. The operators behind OctLurk and SilkLurk bypass this security check by binding execution to unique physical host parameters:
OctLurk Execution Check: Queries the physical hard drive serial number of the host system. If the serial matches the pre-programmed victim key, the loader decrypts the primary payload directly in memory.
SilkLurk Execution Check: Reads the target system's computer name (hostname) to derive the decryption key.
Sandbox Neutralisation: When analysed in an isolated testing environment lacking these specific host parameters, the files remain encrypted and show no malicious behaviour to automated security software.
Modular Multi-Plugin Framework & Post-Exploitation Tactics
Rather than installing an entire suite of hacking tools during initial access, the attackers maintain a minimal footprint by deploying lightweight loaders. Once an initial foothold is secured, the operators fetch specialised modules on demand:
System Command & Automation: Custom plugins take over command shells, execute file system modifications, and synthesise mouse and keyboard events to bypass access controls.
Credential Theft & Network Mapping: Deploying browser password extractors, keyloggers, and specialised tools to collect administrative credentials directly from Domain Controllers managing employee network logins.
Confidential Document Search: Searching shared network drives for restricted documents, which are packaged using standard file compression formats before exfiltration.
Redundant Access Infrastructure: To maintain persistent access if the primary vector is discovered, the attackers deploy secondary channels, including the PlugX Remote Access Trojan (RAT) and legitimate remote monitoring utilities.
Victim Profile & Infrastructure Attribution
Kaspersky identified compromised entities in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The target list includes high-value regional organisations:
| Victim Sector Scope | Compromised Entity Types | Primary Threat Objective |
| Public Sector & Defense | Government Ministries, Law Enforcement Agencies | Strategic intelligence gathering and diplomatic surveillance. |
| Critical Infrastructure | Logistics Providers, Urban Planning & Facilities | Operational tracking and transport network mapping. |
| Research & Healthcare | Educational Institutes, Healthcare Organizations | Proprietary research exfiltration and institutional monitoring. |
While formal attribution to a specific Advanced Persistent Threat (APT) group remains unconfirmed, Kaspersky GReAT assesses with medium confidence that the campaign is driven by Chinese-speaking operators, citing overlaps in PlugX Trojan deployment patterns and shared command-and-control (C2) infrastructure.
Saurabh Sharma, Lead Security Researcher at Kaspersky GReAT, highlighted the trade-off between scale and stealth in targeted cyber espionage:
"Most malware is written once and sent to thousands of targets, which is what makes it easy to catch. Here the attackers gave up that scale on purpose. Preparing a separate build for every victim takes real effort, and it tells you they were more concerned with staying hidden inside a small number of organizations than infecting a lot of them."
Kaspersky recommends that enterprise defenders enforce strict Active Directory governance, monitor for unauthorised scheduled tasks, and implement Endpoint Detection and Response (EDR) solutions capable of detecting in-memory payload injections.
Read More:
Fortinet 2025 Report: The high cost of the security training completion gap
How AI and managed services are transforming BFSI operations
Garmin expands retail network as premium wearable demand grows
Nutanix explains how hybrid multi-cloud services will define channel growth






