OctLurk and SilkLurk campaigns hit Central Asian government networks
Source headline: Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
Intelligence Summary
A Chinese-speaking threat actor is linked to a sustained set of intrusions against government organizations in Central Asia. Targets include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, and Kazakhstan, along with the Syrian Arab Republic. The campaign is associated with malware families named OctLurk and SilkLurk and has been active since January 2025. Compromised entities operate across multiple sectors, including healthcare, research, and government offices. Organizations in the region should review logs for suspicious persistence and remote access activity tied to these campaign indicators.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.