Skip to main content

OctLurk and SilkLurk: new Backdoors in Central Asia

0
Medium
Published: 07/30/2026 (07/30/2026, 13:03:19 UTC)
Source: AlienVault OTX General

Description

Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:42:42 UTC

Technical Analysis

OctLurk and SilkLurk are sophisticated backdoors identified in early 2025 targeting government-related entities across Central Asia and Syria. They utilize heavily obfuscated, victim-specific loaders that decrypt using machine-specific data. Both backdoors support multiple plugins enabling a broad range of malicious activities including command execution, file operations, credential theft, keylogging, network reconnaissance, and remote control. The attackers employ LurkProxy for network traffic proxying and deploy additional tools such as PlugX, Impacket, FSCAN, and Pandora FMS agents to enhance their operational capabilities. Analysis indicates a single Chinese-speaking threat actor operates both backdoors, though no definitive attribution to a known group is established. The campaigns show advanced persistence and evasion mechanisms.

Potential Impact

The backdoors enable attackers to execute arbitrary commands, manipulate files, harvest credentials, log keystrokes, scan networks, and maintain persistent remote access within targeted organizations. This compromises confidentiality, integrity, and availability of affected systems across multiple critical sectors including government, healthcare, and education in Central Asia and Syria. The use of multiple plugins and additional tools increases the attack surface and operational flexibility for the adversary, facilitating extensive espionage and potential disruption activities.

Defensive Guidance

No official patch or remediation guidance is currently available. Organizations in the affected regions should monitor for indicators of compromise related to OctLurk and SilkLurk as described in the referenced analysis. Due to the sophisticated and customized nature of the loaders and plugins, detection may require specialized threat intelligence and behavioral analysis. Incident response teams should consult the detailed vendor analysis at the provided reference link for the latest detection and mitigation recommendations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"]
Pulse Id
6a6b4b97df5f9df74333adfa

Indicators of Compromise

Hash

ValueDescriptionCopy
hash62944e26b36b1dcace429ae26ba66164
hashcf903e4a1629aa0582fd0363b5786676
hash9a1dd1d96481d61934dcc2d568971d06
hash18dc8bff47cc282508354771d0c8cf8c
hashcc5cc2546d3ea8e27250cc4bec24f6ca13caf341
hash23b122deea347dbe2407c1542c1cc6caaafca537eb5d1950a4ed7c8a69395dbb
hash082d49ef9f14e6811d68c7e0e82e5069
hash1415a78b75de7db4ba3d1e61d7db4501
hash2a571f6cee42a17d873f4c942649813f
hash2f18472866f38c1e1c2c5c14b9a6ab56
hash32a5985543433a4f60da2fafd873b927
hash37dc84e4bcad92fa28f1e7778d088283
hash3c9a1ba8e0c7475706adc6376e9d7b7c
hash45cf5916fab4272a1313c26e67aa9220
hash4e6d5c4770d5a822d7fcce6a74f7ad73
hash5e26df131ff0a679a0a2699b723b46e3
hash6ecf84fb18f6747ed08d7598364d853a
hash7c2f64461bb519c6cbf1fc687675514c
hash8269d6ba1b6842f9152c90cf7add9b93
hasha0cc7accc79abb0287aaba825d0351f0
hasha4d550a3ba0cd073fe3839b99d98a7a8
hasha56cce62930a6bee80d679b4c495a340
hashb874123a80fc4f40e06872b9cb54ebc6
hashbe4731c09734da2e8eb6814a9c82f266
hashef59aad625eebda8650aec5820d6ce69
hashf4578e869a735cfad691f927bae3e638

Domain

ValueDescriptionCopy
domainconfbase.mdpsupport.net
domainfm01.clouddevicemetrics.com
domainssl.blsouqs.com
domainabout.blsouqs.com
domainapi2.annoyingremote.com
domainctyuhjerf.kozow.com
domaindigital.leroymerling.com
domaindns.multitoconference.com
domaindns.ssentialserv.xyz
domaingycudore.kozow.com
domainrgnojb.casacam.net
domaintj.tajikistandip.com
domaintyhbgtyuj.gleeze.com
domainuyhvfredc.accesscam.org
domainwedfcvbn.gleeze.com

Threat ID: 6a6c856d9c2644c7f8ba4277

Added to database: 07/31/2026, 11:22:21 UTC

Last enriched: 07/31/2026, 12:42:42 UTC

Last updated: 09/13/2026, 20:14:29 UTC

Views: 300

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses