OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Kaspersky identified two new tailored backdoors, OctLurk and SilkLurk, deployed in a coordinated cyber-espionage campaign targeting government organizations across Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria) since January 2025. Both backdoors feature custom loaders using victim-machine fingerprinting for payload decryption, plugin-based architecture for command shells, file management, keylogging, credential harvesting, and remote access. The campaign demonstrates sophisticated post-compromise activity including event log exfiltration, Impacket secretsdump deployment for domain controller credential theft, and browser password extraction.