The images in this article were generated with artificial intelligence. How we publish
A new front in cyberespionage for public institutions in Central Asia and Syria has been exposed and deserves immediate attention: Kaspersky researchers have described a campaign since January 2025 that employs two families of unpublished backdoors, baptized as OctLurk and SilkLurk, next to a malicious proxy called LurkProxy. Although the authors communicate in Chinese and certain pieces fit into tactics observed in previous operations associated with Chinese-speaking actors, Kaspersky does not conclusively associate these intrusions with a well-known group; the important thing for defenders and IT leaders is the set of technical capabilities and the potential impact on ministries, law enforcement, health, education and other public services.
The sophistication of the campaign lies in its design to operate mostly in memory, leaving only a minimum charger on disk and using equipment-dependent encoding (e.g. disk serial number or equipment name) to hide useful routes and loads; this strategy makes reverse engineering and automated detection by traditional firms difficult. OctLurk is injected into memory from a loader, collects encrypted system information and contacts C2 servers such as "dns.multitococonence [.] com," while SilkLurk arrives by a sequence of DLL side-loading and also receives and injects plugins in memory that allow command execution, exfiltration, and use legitimate tools to pack stolen data. LurkProxy, for its part, acts as a proxy reverse in SOCKS5 or transparent modes to cover up outgoing traffic to remote directions (for example, the IP reported 154.196.162 [.] 76) and thus facilitate lateral movements and exfiltration.

The technical repertoire deployed after the intrusion is wide and reveals espionage and persistence objectives: host footprint, flashing of domain controller hashes with tools such as Impacket (already mentioned in the findings), display of disguised keyloggers (simulating AnyDesk), theft of credentials from browsers, use of a remote control agent called Pandora RC, scanning of internal networks with Fcan and exploitation of credentials for SSH or MySQL, as well as use of PlugX through DLL side-loading chains to introduce another known backdoor in the environment. These practices fit into campaigns aimed at intelligence collection and sustained access rather than immediate destructive operations.
For those responsible for cyberdefence in public organizations and service providers in the region, the implications are clear: the threat prioritizes evasion and persistence, and takes advantage of shared infrastructure with previous campaigns (e.g. SilentRaid / MystRodX / TrustFall), which suggests reused command and control infrastructures and a potential operator with experience in multi-level campaigns. In addition, the lack of knowledge of the initial access vector requires a review of the entire protection chain, from basic account hygiene to network and memory telemetry.
The recommended actions combine immediate measures and strategic controls. In the short term it is appropriate to block and monitor observed indicators (domains such as dns.ssentialserv [.] xyz and dns.multiconference [.] com and IP 154.196.162 [.] 76), audit records of DNS and egress, and quarantine systems with suspicious activity. It is essential to strengthen the protection of domain controllers, apply network segmentation to limit lateral movement, enable multifactor authentication for administrative access, rotate credentials and use mechanisms such as LAPS for local credentials. In endpoints, EDR technologies with memory visibility and process injection detection are critical because these backdoors operate in-memory and evade traditional signatures.

Additional operational measures include restricting the use of unwarranted remote management tools, disabling or restricting the use of accounts with privileges in shared resources, recording and maintaining security events (auth, PowerShell, Sysmon, DNS) to investigate post-commitment, and reviewing file transfers and use of legitimate utilities (WinRAR, 7-Zip) that are used to pack exfiltration. Preparing response playbooks, testing containment and recovery, and sharing findings with national entities and international partners will increase regional resilience to transnational campaigns.
It is also a recommendation to cyber security providers and detection equipment: to generate detection rules focused on behavior patterns (e.g., side-rolling DLL chains, creation of unusual TCP sockets by legitimate processes, use of reverse proxies and credentials dumping activities), and to develop memory / YARA signatures adapted to packaging and host-dependent coding using OctLurk and SilkLurk. To understand specific behavioral techniques and mapping, reference resources such as MITRE ATT & CK can be found in your section about DLL side-rolling https: / / attack.mitre.org / techniques / T1574 / 001 / and follow technical analyses that publish research centres like Kaspersky on your portal https: / / securelist.com /.
Finally, and perhaps most importantly, dealing with this type of campaign requires assuming that perimetral detection alone is not enough: effective defence combines perimeter control, continuous visibility in endpoints and networks, rigorous privilege control and a coordinated response capacity. The organisations concerned or at risk should contact their national CERT or response partners and consider the exchange of indicators and tactics to contain and mitigate these operations before persistent access is consolidated and there is mass exfiltration of sensitive information.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...