Press play to start listening
Kaspersky has identified two previously undocumented Windows backdoors in a cyber-espionage campaign targeting government organizations and public institutions in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and the Syrian Arab Republic since January 2025. The company named the malware OctLurk and SilkLurk.
According to Kaspersky’s report, the affected organizations include healthcare and research bodies, government offices, foreign ministries, logistics providers, law-enforcement agencies, urban planning departments, facilities managers and public educational institutions.
Researchers note that each infection is prepared for a particular computer. OctLurk derives part of its decryption key from the serial number of the C drive, while SilkLurk computes a hash from the computer name. Those values unlock the payload path and malicious code, making each loader specific to its intended victim.
On infected computers, OctLurk is installed through scheduled tasks and malicious Windows services after the attacker obtains administrative credentials. SilkLurk uses legitimate NVIDIA and Realtek programs to side-load malicious DLLs, then creates a service that restarts after a failure. Both backdoors place their main components into memory while leaving a small loader on disk.
After connecting to command servers, OctLurk and SilkLurk can receive and inject additional plugins into memory. These components give the operator command-shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access.
During OctLurk infections, Kaspersky observed the attackers collecting system and network details before deploying tools such as Impacket’s secretsdump, a keylogger, a browser password extractor and the Fscan network scanner. They also installed Pandora remote-control agents and connected directly to email servers using account credentials.
SilkLurk was used to open PowerShell, connect to shared network resources with administrative credentials and search for confidential documents. The attackers compressed collected material with WinRAR or 7-Zip, disconnected from network shares to hide which internal servers had been accessed, and installed the PlugX remote-access malware as a second-stage payload.
Alongside the two backdoors, the attackers deployed LurkProxy, a separate implant built with a design similar to OctLurk. Kaspersky said LurkProxy is not a backdoor. Its main role is to relay network traffic through a TLS-encrypted connection, operating as either a SOCKS5 or transparent reverse proxy.
Kaspersky’s technical report, published on July 30, 2026, also connected part of the command infrastructure to a March 2025 campaign targeting critical infrastructure in Kazakhstan with Linux malware known as TrustFall, MystRodX or SilentRaid.
Researchers also found that three command-server addresses from that campaign were used by OctLurk and LurkProxy, although Kaspersky could not determine whether the operations ran at the same time.
Evidence of common control appeared on the infected systems themselves. Some victims had both backdoors; the malware sometimes used the same staging directories, and Kaspersky saw an OctLurk command shell deliver a SilkLurk loader.
Kaspersky assesses with medium confidence that a Chinese-speaking actor operates both backdoors. The use of PlugX, which has a long history among Chinese-speaking groups, supports that assessment, but researchers have not attributed the campaign to any known threat group.
Kaspersky published file hashes, domains, IP addresses, and file paths that organizations can use to search for related activity. Additional indicators are available to subscribers of its threat intelligence service.