OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
The article describes OctLurk, SilkLurk, and LurkProxy, three closely related implants used since January 2025 against government and other organizations across Central Asia and the Syrian Arab Republic, with victim-specific loaders and heavy obfuscation. The same campaign also included credential theft, keylogging, browser password theft, network scanning, remote access, and the later deployment of PlugX, while infrastructure overlap and shared artifacts suggest a Chinese-speaking threat actor. #OctLurk #SilkLurk #LurkProxy #PlugX

Keypoints

  • OctLurk and SilkLurk are new backdoors observed in attacks starting in January 2025.
  • Victims are mainly government-related organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria.
  • Both backdoors use victim-specific loaders, heavy obfuscation, and in-memory plugin execution.
  • LurkProxy is a related implant that acts as a proxy and shares architectural similarities with OctLurk.
  • Attackers performed fingerprinting, credential harvesting, keylogging, browser password theft, email collection, and network scanning.
  • SilkLurk was used to open a shell and deploy PlugX as a second-stage payload.
  • Infrastructure overlap and shared artifacts suggest the activity is likely operated by the same Chinese-speaking threat actor.

MITRE Techniques

  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Used to execute malicious batch scripts and loaders via tasks named GoogleUpDate and AnyDesk [‘created a scheduled task named GoogleUpDate’ / ‘created a scheduled task named AnyDesk’]
  • [T1543.003 ] Create or Modify System Process: Windows Service – Used services to load malicious DLLs and maintain persistence [‘created a service named NgcCIntSvc’ / ‘created a service named Cusrxsrv’ / ‘creates a service named RmSs’]
  • [T1027 ] Obfuscated Files or Information – Loaders, backdoors, and configuration data were heavily obfuscated and encrypted [‘heavily obfuscated, making analysis more complicated’]
  • [T1055 ] Process Injection – Backdoor DLLs were reflectively injected into memory [‘reflectively injected into memory and its entry point is executed’]
  • [T1105 ] Ingress Tool Transfer – Additional plugins and payloads were downloaded from C2 and injected into memory [‘load plugins from the C2 server directly into memory’ / ‘receive and inject additional payloads’]
  • [T1049 ] System Network Connections Discovery – Used to enumerate listening and established connections [‘Get-NetTCPConnection’ / ‘netstat -ano | findstr LISTENING’]
  • [T1016 ] System Network Configuration Discovery – Collected IP and network configuration details [‘ipconfig /all’ / ‘gwmi Win32_NetworkAdapterConfiguration’]
  • [T1082 ] System Information Discovery – Gathered OS, hardware, BIOS, CPU, memory, and disk information [‘systeminfo’ / ‘Win32_BIOS’ / ‘Win32_Processor’]
  • [T1033 ] System Owner/User Discovery – Retrieved logged-on user and account details [‘WHOAMI /all’ / ‘user’s logon name’]
  • [T1087.001 ] Account Discovery: Local Account – Enumerated local users and profiles [‘reg query HKLM /s /f “ProfileImagePath”’ / ‘dir /b c:users’]
  • [T1135 ] Network Share Discovery – Connected to shared resources and searched shared drives [‘net use to connect to shared network resources’]
  • [T1005 ] Data from Local System – Searched for and collected local files and documents [‘searched the shared drives for confidential documents’]
  • [T1115 ] Clipboard Data – Collected clipboard contents via the keylogger and interaction manager [‘holds clipboard data’ / ‘retrieve clipboard data’]
  • [T1056.001 ] Keylogging – Captured keystrokes and stored them in local files [‘keylogger creates two files … which stores captured keystrokes’]
  • [T1020 ] Data Exfiltration – Used archiving tools to package stolen data for removal [‘To archive the stolen data, they employed … WinRAR and 7-Zip’]
  • [T1003.006 ] OS Credential Dumping: DCSync – Used Impacket secretsdump to extract password hashes from domain controllers [‘portable-executable version of Impacket’s secretsdump.py tool’ / ‘extracted password hashes from domain controllers’]
  • [T1218.011 ] System Binary Proxy Execution: Rundll32 – Not explicitly present; removed.
  • [T1204.002 ] User Execution: Malicious File – Executed disguised binaries and droppers to trigger payloads [‘ran the file … kmsonline.exe’ / ‘dropped and executed a keylogger’]
  • [T1566 ] Phishing – Not mentioned; removed.
  • [T1113 ] Screen Capture – Interaction manager could capture the entire screen as BMP images [‘capture the entire screen as a BMP image’]
  • [T1114.001 ] Email Collection: Local Email Collection – Collected email content via email server interactions [’email harvesting’ / ‘select the Inbox folder’]
  • [T1047 ] Windows Management Instrumentation – Used WMI queries for inventory and discovery [‘Get-WMIObject -Class Win32_BIOS’ / ‘wmic startup get caption,command’]
  • [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell – Used cmd.exe and batch scripts to execute commands [‘launch cmd.exe as shell’ / ‘executing the batch script’]
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – Used PowerShell for discovery and command execution [‘opened a command shell (cmd.exe). Within PowerShell, they ran commands’]
  • [T1090 ] Proxy – LurkProxy functioned as a reverse proxy and proxied traffic through C2 [‘primary role is to proxy network traffic’]

Indicators of Compromise

  • [Domains] C2 and infrastructure – dns[.]multitoconference[.]com, dns[.]ssentialserv[.]xyz, gycudore[.]kozow[.]com, ctyuhjerf[.]kozow[.]com
  • [IP addresses] C2 servers and proxy endpoints – 154[.]196[.]162[.]76, 64[.]7[.]198[.]130
  • [File hashes] loaders/backdoors/tooling – 082d49ef9f14e6811d68c7e0e82e5069, 3c9a1ba8e0c7475706adc6376e9d7b7c, and other hashes such as 2a571f6cee42a17d873f4c942649813f and 37dc84e4bcad92fa28f1e7778d088283
  • [File names] malicious scripts, DLLs, and tools – oleasapi.dll, msbasesysdc.dll, vulkan-1.dll, kmsonline.exe, AnyDesk.exe, fc.exe
  • [File paths] staged payloads and dropped components – C:Users[username]Videos1.bat, C:windowstempin.bat, C:ProgramDataintelvulkan-1.dll, C:UsersPublicLibrariesmsectdev0
  • [Scheduled task names] persistence and execution – GoogleUpDate, AnyDesk
  • [Service names] malicious persistence/loading – NgcCIntSvc, Cusrxsrv, RmSs, specitsrc, cmtastsvc, PNRPHostSvc, vmictimerosync, vmicagent
  • [Other IOCs] archive and loot files – info.txt, .datb, _logs.datb, result.txt


Read more: https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/