The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity firm Kaspersky reports that a suspected Chinese-speaking hacking group has been attacking government organizations in Central Asia and Syria since January 2025.
- The targets span countries including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, across sectors such as healthcare, foreign affairs, law enforcement, logistics, and education.
- The attackers use two new memory-based backdoors, OctLurk and SilkLurk, along with a proxy tool called LurkProxy, enabling them to steal passwords, log keystrokes, take screenshots, harvest email, and move through internal networks.
- The malware leaves little trace on disk and uses victim-specific encoding, making detection and analysis difficult; the report does not tie the activity to any known hacking group.
What to watch next
- Whether Kaspersky or other researchers attribute the campaign to a specific known group.
- How the attackers initially gain access to victim networks, which remains unknown.
- Further details on the infrastructure overlap with the earlier SilentRaid (MystRodX) attacks.
Coverage1
1 report
English national1
All filed from India
Named Afghanistan · Kyrgyzstan · Tajikistan · Uzbekistan · Kazakhstan · Syria · AnyDesk · Fscan · Impacket · Kaspersky · LurkProxy · MystRodX · OctLurk · Pandora RC agent · PlugX · Saurabh Sharma · SilentRaid · SilkLurk
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
