The article describes OctLurk, SilkLurk, and LurkProxy, three closely related implants used since January 2025 against government and other organizations across Central Asia and the Syrian Arab Republic, with victim-specific loaders and heavy obfuscation. The same campaign also included credential theft, keylogging, browser password theft, network scanning, remote access, and the later deployment of PlugX, while infrastructure overlap and shared artifacts suggest a Chinese-speaking threat actor. #OctLurk #SilkLurk #LurkProxy #PlugX
Keypoints
- OctLurk and SilkLurk are new backdoors observed in attacks starting in January 2025.
- Victims are mainly government-related organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria.
- Both backdoors use victim-specific loaders, heavy obfuscation, and in-memory plugin execution.
- LurkProxy is a related implant that acts as a proxy and shares architectural similarities with OctLurk.
- Attackers performed fingerprinting, credential harvesting, keylogging, browser password theft, email collection, and network scanning.
- SilkLurk was used to open a shell and deploy PlugX as a second-stage payload.
- Infrastructure overlap and shared artifacts suggest the activity is likely operated by the same Chinese-speaking threat actor.
MITRE Techniques
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Used to execute malicious batch scripts and loaders via tasks named GoogleUpDate and AnyDesk [âcreated a scheduled task named GoogleUpDateâ / âcreated a scheduled task named AnyDeskâ]
- [T1543.003 ] Create or Modify System Process: Windows Service â Used services to load malicious DLLs and maintain persistence [âcreated a service named NgcCIntSvcâ / âcreated a service named Cusrxsrvâ / âcreates a service named RmSsâ]
- [T1027 ] Obfuscated Files or Information â Loaders, backdoors, and configuration data were heavily obfuscated and encrypted [âheavily obfuscated, making analysis more complicatedâ]
- [T1055 ] Process Injection â Backdoor DLLs were reflectively injected into memory [âreflectively injected into memory and its entry point is executedâ]
- [T1105 ] Ingress Tool Transfer â Additional plugins and payloads were downloaded from C2 and injected into memory [âload plugins from the C2 server directly into memoryâ / âreceive and inject additional payloadsâ]
- [T1049 ] System Network Connections Discovery â Used to enumerate listening and established connections [âGet-NetTCPConnectionâ / ânetstat -ano | findstr LISTENINGâ]
- [T1016 ] System Network Configuration Discovery â Collected IP and network configuration details [âipconfig /allâ / âgwmi Win32_NetworkAdapterConfigurationâ]
- [T1082 ] System Information Discovery â Gathered OS, hardware, BIOS, CPU, memory, and disk information [âsysteminfoâ / âWin32_BIOSâ / âWin32_Processorâ]
- [T1033 ] System Owner/User Discovery â Retrieved logged-on user and account details [âWHOAMI /allâ / âuserâs logon nameâ]
- [T1087.001 ] Account Discovery: Local Account â Enumerated local users and profiles [âreg query HKLM /s /f âProfileImagePathââ / âdir /b c:usersâ]
- [T1135 ] Network Share Discovery â Connected to shared resources and searched shared drives [ânet use to connect to shared network resourcesâ]
- [T1005 ] Data from Local System â Searched for and collected local files and documents [âsearched the shared drives for confidential documentsâ]
- [T1115 ] Clipboard Data â Collected clipboard contents via the keylogger and interaction manager [âholds clipboard dataâ / âretrieve clipboard dataâ]
- [T1056.001 ] Keylogging â Captured keystrokes and stored them in local files [âkeylogger creates two files ⌠which stores captured keystrokesâ]
- [T1020 ] Data Exfiltration â Used archiving tools to package stolen data for removal [âTo archive the stolen data, they employed ⌠WinRAR and 7-Zipâ]
- [T1003.006 ] OS Credential Dumping: DCSync â Used Impacket secretsdump to extract password hashes from domain controllers [âportable-executable version of Impacketâs secretsdump.py toolâ / âextracted password hashes from domain controllersâ]
- [T1218.011 ] System Binary Proxy Execution: Rundll32 â Not explicitly present; removed.
- [T1204.002 ] User Execution: Malicious File â Executed disguised binaries and droppers to trigger payloads [âran the file ⌠kmsonline.exeâ / âdropped and executed a keyloggerâ]
- [T1566 ] Phishing â Not mentioned; removed.
- [T1113 ] Screen Capture â Interaction manager could capture the entire screen as BMP images [âcapture the entire screen as a BMP imageâ]
- [T1114.001 ] Email Collection: Local Email Collection â Collected email content via email server interactions [âemail harvestingâ / âselect the Inbox folderâ]
- [T1047 ] Windows Management Instrumentation â Used WMI queries for inventory and discovery [âGet-WMIObject -Class Win32_BIOSâ / âwmic startup get caption,commandâ]
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell â Used cmd.exe and batch scripts to execute commands [âlaunch cmd.exe as shellâ / âexecuting the batch scriptâ]
- [T1059.001 ] Command and Scripting Interpreter: PowerShell â Used PowerShell for discovery and command execution [âopened a command shell (cmd.exe). Within PowerShell, they ran commandsâ]
- [T1090 ] Proxy â LurkProxy functioned as a reverse proxy and proxied traffic through C2 [âprimary role is to proxy network trafficâ]
Indicators of Compromise
- [Domains] C2 and infrastructure â dns[.]multitoconference[.]com, dns[.]ssentialserv[.]xyz, gycudore[.]kozow[.]com, ctyuhjerf[.]kozow[.]com
- [IP addresses] C2 servers and proxy endpoints â 154[.]196[.]162[.]76, 64[.]7[.]198[.]130
- [File hashes] loaders/backdoors/tooling â 082d49ef9f14e6811d68c7e0e82e5069, 3c9a1ba8e0c7475706adc6376e9d7b7c, and other hashes such as 2a571f6cee42a17d873f4c942649813f and 37dc84e4bcad92fa28f1e7778d088283
- [File names] malicious scripts, DLLs, and tools â oleasapi.dll, msbasesysdc.dll, vulkan-1.dll, kmsonline.exe, AnyDesk.exe, fc.exe
- [File paths] staged payloads and dropped components â C:Users[username]Videos1.bat, C:windowstempin.bat, C:ProgramDataintelvulkan-1.dll, C:UsersPublicLibrariesmsectdev0
- [Scheduled task names] persistence and execution â GoogleUpDate, AnyDesk
- [Service names] malicious persistence/loading â NgcCIntSvc, Cusrxsrv, RmSs, specitsrc, cmtastsvc, PNRPHostSvc, vmictimerosync, vmicagent
- [Other IOCs] archive and loot files â info.txt, .datb, _logs.datb, result.txt
Read more: https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/