OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft — Threadlinqs Intelligence
As of 2026-07-31, OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft is a high-severity malware threat attributed to Unattributed Chinese-speaking threat cluster (OctLurk (China (assessed, medium confidence — not attributed to a named APT)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 39 indicators of compromise.
Threat ID: TL-2026-1786 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unattributed Chinese-speaking threat cluster (OctLurk · China (assessed, medium confidence — not attributed to a named APT) · ESPIONAGE
A likely Chinese-speaking threat actor has deployed custom backdoors OctLurk, SilkLurk, and the LurkProxy relay component (alongside PlugX) against government, law enforcement, healthcare, research,
OctLurk and SilkLurk are two custom, primarily in-memory backdoors first documented by Kaspersky's GReAT team on Securelist in a cyber-espionage campaign active since at least January 2025 against government and critical-sector organizations across Central Asia (Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan) and Syria. Kaspersky assesses with medium confidence that a single, unattributed Chinese-speaking threat actor operates both malware families; some victims infected with SilkLurk were also found running OctLurk, and overlapping staging directories (C:\ProgramData\intel\) link the two toolsets together.
Initial access is achieved using stolen administrator credentials, which the operator uses to create a scheduled task (GoogleUpDate) that runs a batch script installing a Windows service (NgcCIntSvc) that loads the OctLurk loader DLL (oleasapi.dll). SilkLurk instead relies on DLL side-loading through legitimate signed binaries (NetSetSvc.exe, nvgwls.exe, RtkSmbus.exe, RtkNGUI64.exe) paired with a malicious service (RmSs). Both loaders decrypt their payloads using victim-specific values — the C: drive serial number for OctLurk, a hash of the computer name for SilkLurk — so sandboxes cannot decrypt or execute the backdoor outside the intended host. Both backdoors run reflectively injected in memory and download plugins from the C2 to perform file management, command-shell execution, screen capture, clipboard monitoring, keyboard/mouse simulation, and network scanning.
A related component, LurkProxy, shares OctLurk's architecture but functions purely as a SOCKS5/transparent network relay (listening on TCP/64980), letting the operator route additional intrusion tooling through compromised hosts. The actor also deploys the well-known Chinese-linked PlugX RAT (via a dropper masquerading as kmsonline.exe, injected into svchost.exe, campaign ID KG_MFA) alongside a credential-dumping toolkit — Impacket secretsdump run against domain controllers, a browser-credential-recovery utility targeting Chrome and Firefox, a custom keylogger, and the Fscan network scanner used to brute-force SSH and MySQL services for lateral movement. Post-compromise, operators harvest email over IMAP, enumerate SMB shares, and stage stolen documents with WinRAR/7-Zip prior to exfiltration, while also deploying the Pandora FMS remote-access agent for persistent control.
Kaspersky further notes that OctLurk and LurkProxy C2 infrastructure overlaps with 'TrustFall' — a Linux-targeting RAT (also tracked as MystRodX by Qianxin and SilentRaid by Cisco Talos) that Kazakhstan's State Technical Service reported against national critical infrastructure in March 2025, with additional TrustFall C2 servers discovered in October 2025 — suggesting the same infrastructure, and possibly the same operator, supports parallel Windows- and Linux-targeting campaigns.
The TrustFall/MystRodX/SilentRaid lineage that Kaspersky ties to OctLurk/LurkProxy predates the January 2025 Central Asia campaign by over a year. QiAnXin XLab's September 2025 technical analysis of MystRodX found sample activation timestamps as early as 7 January 2024, and Palo Alto Networks Unit 42 had separately documented what it assesses to be an earlier iteration of the same tool — dubbed 'ChronosRAT' — inside intrusion cluster CL-STA-0969, active against Southwest/Southeast Asian telecom networks between February and November 2024. On 8 January 2026, Cisco Talos published its own attribution of the SilentRaid backdoor to a distinct China-nexus actor it tracks as UAT-7290, assessed active since at least 2022 against South Asian telecom infrastructure (with recent expansion into Southeastern Europe), and found tooling/infrastructure overlaps with Red Foxtrot, APT10/MenuPass (via RedLeaves), and ShadowPad. Kaspersky's linkage is limited to C2 infrastructure overlap between OctLurk/LurkProxy and TrustFall — it does not itself confirm UAT-7290 as the OctLurk/SilkLurk operator — but it places the sh
Target sectors: government administration, police - law enforcement, health, research, logistics, education, urban planning, facilities management, foreign affairs
Target regions: 143 - Central Asia, South Asia, Middle East
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 39 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1078, T1059.003, T1053.005, T1543.003, T1574.001, T1055, T1027, T1140, T1685, T1055