**Chinese-Speaking Threat Actors Deploy Advanced Backdoors in Central Asian Cyber Espionage Campaign**
Kaspersky researchers have uncovered a sophisticated cyber espionage campaign targeting government organizations across Central Asia and the Middle East. Since January 2025, a Chinese-speaking threat actor has been deploying two new obfuscated backdoors—OctLurk and SilkLurk—alongside a traffic proxying tool called LurkProxy to compromise systems in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.
The attacks have specifically targeted sectors including healthcare, research, government offices, foreign ministries, law enforcement, logistics, urban planning, and educational institutions. Notably, the activity has not yet been linked to any known advanced persistent threat (APT) group.
### **Modus Operandi and Technical Analysis**
The initial access vector remains unclear, but Kaspersky’s analysis reveals a multi-stage infection process. OctLurk is injected into memory and deployed via a loader that checks for connectivity to a specific domain before executing a batch script that launches LurkProxy. The tool then contacts a remote command-and-control (C2) server.
Once active, OctLurk collects system information, encrypts it, and sends it to a hard-coded C2 server. It is capable of loading additional plugins directly into memory, enabling functionalities such as:
– Command shell execution
– File system manipulation
– Clipboard harvesting
– Screenshot capture
– Keystroke logging
– Browser password theft
– Email collection
– Remote access
The threat actors have leveraged the command shell plugin to perform fingerprinting, harvest password hashes using tools like Impacket’s secretsdump.py, deploy keyloggers disguised as AnyDesk, and exfiltrate stored credentials from Google Chrome and Mozilla Firefox. The malware also supports network scanning via Fscan and email server compromise to manipulate emails.
LurkProxy operates as either a SOCKS5 or transparent proxy, routing traffic through specified targets. Meanwhile, SilkLurk is delivered via a DLL side-loading technique, establishes a TCP connection to its C2 server, and transmits victim data. It can also execute commands to check system time, adjust polling intervals, update configurations, and inject additional plugins.
Kaspersky notes significant infrastructure overlap between this campaign and a prior attack chain involving the SilentRaid implant, suggesting a shared operational framework. The use of memory-resident malware and machine-specific decoding routines—such as using drive serial numbers or computer names—makes detection and reverse engineering significantly more difficult.
### **FAQ**
**Q: Which countries are being targeted in this campaign?**
A: The primary targets include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.
**Q: What sectors are most affected?**
A: The attacks have focused on healthcare, research institutions, government offices, foreign affairs ministries, law enforcement, logistics, urban planning, and public educational facilities.
**Q: What are the names of the malicious tools used?**
A: The tools identified are OctLurk, SilkLurk, and LurkProxy.
**Q: Who is behind this campaign?**
A: The threat actor is Chinese-speaking, but the specific group or individual has not been identified or linked to any known APT organization.
**Q: How does the malware avoid detection?**
A: The malware operates primarily in memory, leaves minimal traces on disk, and uses machine-specific data to encode its payloads, making detection and analysis more challenging.
**Q: Is there any known attribution to a specific hacking group?**
A: Not yet. Kaspersky has not linked the campaign to any known APT group, though infrastructure overlaps with previous campaigns suggest possible connections.
### **Conclusion**
This campaign represents a significant evolution in cyber espionage tactics within the targeted regions. The deployment of sophisticated, memory-resident malware such as OctLurk and SilkLurk—combined with proxy tools like LurkProxy—demonstrates the attacker’s intent to remain stealthy and persistent. The broad scope of sectors targeted and the advanced capabilities of the tools highlight the growing sophistication of Chinese-speaking cyber threat actors. Continued vigilance, improved detection mechanisms, and cross-sector information sharing will be critical in mitigating such threats in the future.



