Top Highlights
- Chinese threat actors are deploying sophisticated, memory-resident backdoors (OctLurk and SilkLurk) to conduct extensive cyber espionage, including data theft, network scanning, and remote access via custom plugins and proxy utilities.
- They leverage DLL side-loading and encrypted, victim-specific encoding to evade detection, establishing persistent footholds with minimal disk footprint and dynamic, memory-based malicious activity.
- The attackers target critical sectors in Central Asia with tools capable of extracting sensitive credentials, compromising network infrastructure, and deploying backdoors like PlugX and Pandora RC for ongoing control.
Threat, Attack Techniques, and Targets
A Chinese-speaking threat actor is suspected of launching a series of cyber attacks since January 2025. These attacks mainly target government organizations in Central Asia. The victims include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. The targeted sectors cover healthcare, research, government offices, law enforcement, urban planning, and educational institutions.
The attackers use two new obfuscated backdoors named OctLurk and SilkLurk. They also use a tool called LurkProxy to route network traffic. These backdoors can upload and run additional plugins to do malicious tasks. They perform actions such as file management, network scanning, keylogging, stealing passwords, and remote control.
The initial access method is not clear. However, OctLurk is injected into memory through a loader. It checks a domain called “dns.ssentialserv[.]xyz” before launching a script that activates LurkProxy. OctLurk then connects to a command-and-control (C2) server to receive commands. It gathers system data, encrypts it, and sends it to a C2 server at “dns.multitoconference[.]com”. It can also load plugins into memory to execute commands like remote access, password dumping, and network scanning. SilkLurk is launched via DLL side-loading and creates a TCP socket to communicate with its C2 server. The threat actors exploit shared network resources and use legitimate tools to steal data.
Impact, Security Implications, and Remediation Guidance
This campaign can significantly impact affected organizations. The threat actor can steal sensitive data, control infected systems remotely, and conduct network reconnaissance. They may also introduce additional malware such as PlugX via DLL side-loading. The use of memory-resident malware and victim-specific encoding makes detection difficult and increases the risk of prolonged undetected presence.
The security implications include the potential compromise of confidential government and organizational data. The attack techniques demonstrate advanced methods to evade detection and maintain control over targeted networks. Protecting against these threats requires updated security measures.
If organizations suspect infection, they should consult with cybersecurity professionals or the relevant authority. It is important to obtain specific remediation guidance from the security vendors involved. General practices include scanning systems with reputable anti-malware tools, monitoring network traffic for unusual activity, and reviewing network shares and remote access logs. Ensuring all software is up to date and restricting network sharing can also help reduce risks.
Stay Ahead with the Latest Tech Trends
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
