Cyber-espionage alert: OctLurk and SilkLurk attack public institutions in Central Asia and Syria through payloads in memory

Author: Published 4 min de lectura 190 reading

The images in this article were generated with artificial intelligence. How we publish

A new front in cyberespionage for public institutions in Central Asia and Syria has been exposed and deserves immediate attention: Kaspersky researchers have described a campaign since January 2025 that employs two families of unpublished backdoors, baptized as OctLurk and SilkLurk, next to a malicious proxy called LurkProxy. Although the authors communicate in Chinese and certain pieces fit into tactics observed in previous operations associated with Chinese-speaking actors, Kaspersky does not conclusively associate these intrusions with a well-known group; the important thing for defenders and IT leaders is the set of technical capabilities and the potential impact on ministries, law enforcement, health, education and other public services.

The sophistication of the campaign lies in its design to operate mostly in memory, leaving only a minimum charger on disk and using equipment-dependent encoding (e.g. disk serial number or equipment name) to hide useful routes and loads; this strategy makes reverse engineering and automated detection by traditional firms difficult. OctLurk is injected into memory from a loader, collects encrypted system information and contacts C2 servers such as "dns.multitococonence [.] com," while SilkLurk arrives by a sequence of DLL side-loading and also receives and injects plugins in memory that allow command execution, exfiltration, and use legitimate tools to pack stolen data. LurkProxy, for its part, acts as a proxy reverse in SOCKS5 or transparent modes to cover up outgoing traffic to remote directions (for example, the IP reported 154.196.162 [.] 76) and thus facilitate lateral movements and exfiltration.

Cyber-espionage alert: OctLurk and SilkLurk attack public institutions in Central Asia and Syria through payloads in memory
Image generated with IA.

The technical repertoire deployed after the intrusion is wide and reveals espionage and persistence objectives: host footprint, flashing of domain controller hashes with tools such as Impacket (already mentioned in the findings), display of disguised keyloggers (simulating AnyDesk), theft of credentials from browsers, use of a remote control agent called Pandora RC, scanning of internal networks with Fcan and exploitation of credentials for SSH or MySQL, as well as use of PlugX through DLL side-loading chains to introduce another known backdoor in the environment. These practices fit into campaigns aimed at intelligence collection and sustained access rather than immediate destructive operations.

For those responsible for cyberdefence in public organizations and service providers in the region, the implications are clear: the threat prioritizes evasion and persistence, and takes advantage of shared infrastructure with previous campaigns (e.g. SilentRaid / MystRodX / TrustFall), which suggests reused command and control infrastructures and a potential operator with experience in multi-level campaigns. In addition, the lack of knowledge of the initial access vector requires a review of the entire protection chain, from basic account hygiene to network and memory telemetry.

The recommended actions combine immediate measures and strategic controls. In the short term it is appropriate to block and monitor observed indicators (domains such as dns.ssentialserv [.] xyz and dns.multiconference [.] com and IP 154.196.162 [.] 76), audit records of DNS and egress, and quarantine systems with suspicious activity. It is essential to strengthen the protection of domain controllers, apply network segmentation to limit lateral movement, enable multifactor authentication for administrative access, rotate credentials and use mechanisms such as LAPS for local credentials. In endpoints, EDR technologies with memory visibility and process injection detection are critical because these backdoors operate in-memory and evade traditional signatures.

Cyber-espionage alert: OctLurk and SilkLurk attack public institutions in Central Asia and Syria through payloads in memory
Image generated with IA.

Additional operational measures include restricting the use of unwarranted remote management tools, disabling or restricting the use of accounts with privileges in shared resources, recording and maintaining security events (auth, PowerShell, Sysmon, DNS) to investigate post-commitment, and reviewing file transfers and use of legitimate utilities (WinRAR, 7-Zip) that are used to pack exfiltration. Preparing response playbooks, testing containment and recovery, and sharing findings with national entities and international partners will increase regional resilience to transnational campaigns.

It is also a recommendation to cyber security providers and detection equipment: to generate detection rules focused on behavior patterns (e.g., side-rolling DLL chains, creation of unusual TCP sockets by legitimate processes, use of reverse proxies and credentials dumping activities), and to develop memory / YARA signatures adapted to packaging and host-dependent coding using OctLurk and SilkLurk. To understand specific behavioral techniques and mapping, reference resources such as MITRE ATT & CK can be found in your section about DLL side-rolling https: / / attack.mitre.org / techniques / T1574 / 001 / and follow technical analyses that publish research centres like Kaspersky on your portal https: / / securelist.com /.

Finally, and perhaps most importantly, dealing with this type of campaign requires assuming that perimetral detection alone is not enough: effective defence combines perimeter control, continuous visibility in endpoints and networks, rigorous privilege control and a coordinated response capacity. The organisations concerned or at risk should contact their national CERT or response partners and consider the exchange of indicators and tactics to contain and mitigate these operations before persistent access is consolidated and there is mass exfiltration of sensitive information.

Coverage

Related

More news on the same subject.