Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Suspected Chinese-Speaking Hackers Unleash Complex Malware Campaign Targeting Central Asian Governments



A suspected group of Chinese-speaking hackers has been linked to a surge in recent cyber attacks targeting government organizations in Central Asia. The attackers use advanced malware techniques, including OctLurk and SilkLurk backdoors, to compromise sensitive data and disrupt critical infrastructure. This article delves into the details of the attack campaign, highlighting the sophistication and persistence of threat actors and emphasizing the importance of ongoing threat intelligence and incident response efforts.

  • The recent surge in cyber attacks has been attributed to a group of suspected Chinese-speaking hackers targeting government organizations in Central Asia since January 2025.
  • The attackers are believed to be using advanced malware techniques, including OctLurk and SilkLurk backdoors, to compromise sensitive data and disrupt critical infrastructure.
  • OctLurk is an obfuscated backdoor that can download and inject additional plugins to perform further malicious actions, while SilkLurk creates a TCP socket and connects to a C2 server for command-and-control.
  • The threat actors have been found to leverage the backdoors to perform various actions, including fingerprinting the host, harvesting extensive data about the compromised system, and decrypting passwords from Google Chrome and Mozilla Firefox.
  • The attackers also run "cmd.exe" to initiate a DLL side-loading chain to drop PlugX, a known backdoor used by Chinese hacking groups, and connect to an email server to authenticate with a username and password.



  • A recent surge in cyber attacks has been attributed to a group of suspected Chinese-speaking hackers who have been targeting government organizations in Central Asia since January 2025. The attackers, who are believed to be using advanced malware techniques, have been leaving a trail of destruction in their wake, compromising sensitive data and disrupting critical infrastructure.

    The malware used by the hackers is called OctLurk and SilkLurk, which are two new obfuscated backdoors that have been tracked by Russian cybersecurity company Kaspersky. The malware is capable of downloading and injecting additional plugins to perform further malicious actions, including launching command shells, performing file system activity, synthesizing keyboard and mouse events, network scanning, credential dumping, keylogging, password theft from browsers, email collection, and remote access.

    The initial access vector used in these attacks is currently unknown, but Kaspersky analysis has found that OctLurk is injected into memory and deployed by means of a loader, with the attackers also checking internet connectivity to the domain "dns.ssentialserv[.]xyz" before executing a batch script responsible for launching LurkProxy. The tool then establishes contact with a remote server ("154.196.162[.]76") for command-and-control (C2).

    Once run, OctoLurk first collects system information, encrypts it, and sends it to a hard-coded C2 server ("dns.multitoconference[.]com") over a stream socket connection. It's equipped to load plugins received from the server directly into memory to enable command execution, file operations, clipboard content gathering and modification, screenshot capture, and mouse movements.

    The threat actors have been found to leverage the backdoor's command shell plugin to perform a series of actions, including fingerprinting the host and harvesting extensive data about the compromised system. They also run commands to export successful logon events for remote interactive logons and query those events for specific users. Furthermore, they harvest password hashes from domain controllers using Impacket's "secretsdump.py" tool.

    In addition, they drop and execute a keylogger that masquerades as AnyDesk to sidestep detection, decrypt and extract passwords from Google Chrome and Mozilla Firefox, establish remote access to the victim machine using Pandora RC agent, scan internal and public networks using Fscan to identify services running on specific ports, connect to an email server, authenticate with a username and password, and issue commands to collect or manipulate emails.

    The third tool in the threat actor's arsenal is SilkLurk, which is launched by means of a DLL that, in turn, is executed using a DLL side-loading sequence. The backdoor then creates a TCP socket and connects to a C2 server specified in its configuration, followed by collecting victim information and transmitting it to the server.

    In response, the server sends a command that's to be executed on the infected endpoint. This can involve getting the system's local time, setting a sleep interval that determines the frequency at which the backdoor polls the C2 server, sending or updating backdoor configuration, and receiving and injecting additional plugins into memory.

    The post-compromise activity linked to SilkLurk is below - invoke "cmd.exe" to launch PowerShell and run commands to connect to shared network resources with administrative credentials, search and stage confidential documents, disconnect from the network shares, and use legitimate archiving tools like WinRAR and 7-Zip to archive the stolen data.

    Furthermore, they run "cmd.exe" to initiate a DLL side-loading chain to drop PlugX, a known backdoor used by Chinese hacking groups. Kaspersky said it found infrastructure overlaps between the campaign and a prior set of attacks involving a C++-based implant codenamed SilentRaid (aka MystRodX and TrustFall).

    "This overlap points to shared infrastructure across multiple OS-targeting campaigns, though it remains unclear whether these activities ran concurrently or at different times," Kaspersky said. "The emergence of the OctLurk and SilkLurk multi-plugin malware framework highlights how threat actors continuously refine their tactics to evade detection and maintain control over compromised networks."

    "Both families operate primarily in memory, leaving only a minimalistic loader on disk that relies on machine-specific data (OctLurk uses the drive serial number, and SilkLurk uses the computer name) to decode payload locations and contents. This victim-specific encoding makes reverse engineering and automated detection considerably harder."

    The attack campaign is believed to be linked to a group of Chinese-speaking hackers who have been targeting government organizations in Central Asia since January 2025. The attackers use advanced malware techniques, including OctLurk and SilkLurk backdoors, to compromise sensitive data and disrupt critical infrastructure.

    The threat actors have been found to leverage the backdoor's command shell plugin to perform a series of actions, including fingerprinting the host and harvesting extensive data about the compromised system. They also run commands to export successful logon events for remote interactive logons and query those events for specific users.

    In addition, they harvest password hashes from domain controllers using Impacket's "secretsdump.py" tool, drop and execute a keylogger that masquerades as AnyDesk to sidestep detection, decrypt and extract passwords from Google Chrome and Mozilla Firefox, establish remote access to the victim machine using Pandora RC agent, scan internal and public networks using Fscan to identify services running on specific ports.

    The threat actors have also been found to connect to an email server, authenticate with a username and password, and issue commands to collect or manipulate emails. Furthermore, they run "cmd.exe" to initiate a DLL side-loading chain to drop PlugX, a known backdoor used by Chinese hacking groups.

    The attack campaign is believed to be linked to a group of Chinese-speaking hackers who have been targeting government organizations in Central Asia since January 2025. The attackers use advanced malware techniques, including OctLurk and SilkLurk backdoors, to compromise sensitive data and disrupt critical infrastructure.

    In conclusion, the recent surge in cyber attacks attributed to Chinese-speaking hackers is a cause for concern for governments and organizations in Central Asia. The use of advanced malware techniques, such as OctLurk and SilkLurk backdoors, highlights the sophistication and persistence of threat actors.

    The emergence of these multi-plugin malware frameworks also underscores the importance of ongoing threat intelligence and incident response efforts to stay ahead of evolving threat actor tactics. It is essential for organizations to maintain robust cybersecurity defenses and conduct regular vulnerability assessments to mitigate the impact of such attacks.

    Furthermore, it is crucial for governments to establish clear policies and guidelines on data protection and cybersecurity, as well as collaborate with international partners to share intelligence and best practices in combating cyber threats.

    Ultimately, the ongoing threat posed by these Chinese-speaking hackers requires a concerted effort from governments, organizations, and individuals to enhance our collective defenses against evolving cyber threats.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Suspected-Chinese-Speaking-Hackers-Unleash-Complex-Malware-Campaign-Targeting-Central-Asian-Governments-ehn.shtml

  • https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html


  • Published: Fri Jul 31 14:34:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us