OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting Central Asian Government and Critical Infrastructure — Threadlinqs Intelligence
As of 2026-07-31, OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting Central Asian Government and Critical Infrastructure is a high-severity malware threat attributed to Unattributed Chinese-speaking cluster (OctLurk (China (assessed, medium confidence; unattributed to a known group)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 73 indicators of compromise.
Threat ID: TL-2026-1783 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unattributed Chinese-speaking cluster (OctLurk · China (assessed, medium confidence; unattributed to a known group) · ESPIONAGE
Since January 2025, an unattributed Chinese-speaking threat actor has deployed the memory-resident OctLurk and SilkLurk backdoors — alongside the LurkProxy network proxy tool and the
OctLurk and SilkLurk are two related but distinct memory-resident backdoor families first documented in full by Kaspersky's Global Research and Analysis Team (GReAT) on 2026-07-30 (Securelist). Both are attributed with medium confidence to the same unnamed, Chinese-speaking threat cluster, active since at least January 2025 against government ministries (particularly foreign affairs), law enforcement, healthcare, research institutions, logistics, urban planning/facilities management, and public education organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria.
OctLurk is delivered via a victim-specific loader (masquerading as files such as oleasapi.dll, msbasesysdc.dll, and mscastrac.dll, exporting Refresh/RegisterService) that is installed as the malicious Windows service NgcCIntSvc. The loader decrypts its payload with a double-XOR scheme — one hardcoded key plus a second key derived from the victim's C: drive serial number — followed by zlib decompression, then reflectively injects the backdoor into memory. OctLurk supports a plugin system (Command Shell, File Manager, and Interaction Manager for synthetic keyboard/mouse input and screen capture) and communicates over TLS/443 to a set of typosquatted C2 domains.
SilkLurk instead relies on classic DLL side-loading: legitimate signed binaries (NetSetSvc.exe, and Realtek/NVIDIA utilities such as nvgwls.exe, RtkSmbus.exe, RtkNGUI64.exe) load malicious companion DLLs (nvml.dll, vulkan-1.dll, RtkSmbusLoc.dll, RtkNGUI64Loc.dll) that decrypt an encrypted payload blob (e.g., OneDrive.dat) using a key derived from a 32-bit hash of the victim's hostname, then persist via the service name RmSs. SilkLurk's 0x4AC-byte configuration block carries up to four C2 host/port pairs plus proxy credentials, supports HTTP CONNECT proxying that mimics a Chrome/86 user agent, and can inject secondary payloads — including the modular PlugX RAT (service SymantecRAS, campaign ID KG_MFA, C2 gycudore[.]kozow[.]com / 64.7.198.130, injected into svchost.exe).
LurkProxy is a companion utility, architecturally derived from the OctLurk loader, that is not itself a backdoor but a reverse-proxy implant supporting two modes: a C2-mediated SOCKS5 reverse proxy and a transparent proxy with a fixed hardcoded backend, listening locally on port 64980 and using the same zlib + double-XOR protocol as OctLurk.
Post-compromise tradecraft is consistent across victims: a batch-script reconnaissance phase (in.bat / 1.bat / auto.bat) enumerates sessions, Kerberos tickets, processes, RDP logon events, network configuration, AV status, scheduled tasks, and hardware/BIOS data; credential theft follows via Impacket secretsdump disguised as Adobe.exe (LSASS/domain-controller hash extraction), an AnyDesk.exe-named keylogger, and a custom Chrome/Firefox password decryptor (64.exe); the FSCAN utility (fc.exe) then brute-forces and scans internal/public networks (SSH/22, MySQL/3306); lateral movement uses mounted administrative shares; and exfiltration stages sensitive documents into WinRAR/7-Zip archives moved off-network via PowerShell and net use. Kaspersky additionally observed deployment of a Pandora FMS remote-control agent for persistent remote access.
Infrastructure analysis found three C2 IP addresses shared between OctLurk/LurkProxy and the TrustFall Linux backdoor — also tracked as MystRodX (QiAnXin XLab) and SilentRaid (Cisco Talos) — which Kazakhstan's State Technical Service (STS) first publicly reported in March 2025 against Kazakh critical infrastructure, with additional TrustFall C2 servers identified via active probing in October 2025. Shared staging directories (C:\ProgramData\intel\) and identical post-compromise methodology across victims infected with both OctLurk and SilkLurk further support single-operator attribution. No CVE or software vulnerability is implicated; initial access appears credential- or phishing-driven rather than exploit-driven.
XLab's CTIA telemetry firs
Target sectors: government administration, ministries-of-foreign-affairs, police - law enforcement, health, research-institutions, logistics, urban-planning-facilities-management, public-education, critical-infrastructure
Target regions: 143 - Central Asia, afghanistan, kyrgyzstan, tajikistan, uzbekistan, kazakhstan, syria
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 73 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1059, T1106, T1053, T1543, T1554, T1574, T1027, T1140, T1070