A suspected Chinese-speaking threat actor has launched a new campaign against government-related organizations across Central Asia and the Syrian Arab Republic using the backdoors OctLurk and SilkLurk, alongside the proxying tool LurkProxy. The malware operates largely in memory, supports extensive post-compromise activity, and shows infrastructure overlap with the SilentRaid, MystRodX, and TrustFall campaigns. #OctLurk #SilkLurk #LurkProxy #SilentRaid #MystRodX #TrustFall
Keypoints
- Government and public-sector targets across Central Asia have been hit since January 2025.
- OctLurk and SilkLurk are new obfuscated backdoors used in the campaign.
- LurkProxy is used to route traffic as either a SOCKS5 proxy or a transparent proxy.
- The attackers perform credential theft, logging, network scanning, and remote access.
- The campaign overlaps with infrastructure linked to SilentRaid, MystRodX, and TrustFall.
Read More: https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html