Regions Targeted: Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, Uzbekistan
Related Families: OctLurk, SilkLurk, LurkProxy, PlugX
Key Takeaways
Background
The OctLurk and SilkLurk campaign demonstrates a mature post-compromise framework designed for long-term cyber espionage operations. Rather than relying on a single implant, the operators deploy multiple modular components capable of remote administration, credential harvesting, network discovery, file collection, and plugin delivery. Both malware families use victim-specific system attributes to decrypt payload locations and malicious code, making payload decryption dependent on the targeted system and significantly increasing the difficulty of static detection and automated reverse engineering. Combined with heavy code obfuscation and reflective in-memory loading, these capabilities demonstrate a deliberate effort to minimize forensic artifacts while maintaining persistent access to compromised environments.
Kaspersky observed the campaign targeting organizations beginning in January 2025, with identified victims located in Afghanistan, Kazakhstan, Kyrgyzstan, the Syrian Arab Republic, Tajikistan, and Uzbekistan. Affected organizations include government offices, ministries of foreign affairs, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning and facilities management organizations, and public educational establishments. During post-compromise activity, operators expanded their foothold using legitimate administration software alongside publicly available offensive tools, including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX.
Technical Details
OctLurk
OctLurk is a modular backdoor delivered through customized loader DLLs that establish persistence using Windows services and scheduled tasks. Each loader decrypts its payload using a combination of hard-coded keys and the victim system's drive serial number before reflectively injecting the backdoor into memory. Once active, OctLurk collects host information, establishes encrypted communications with its C2 infrastructure, and downloads plugins directly into memory from the C2 server. These plugins provide command shell access, filesystem management, screenshot capture, clipboard interaction, keyboard and mouse simulation, and additional remote administration capabilities. During observed intrusions, operators used OctLurk to perform extensive host reconnaissance, collect event logs, harvest credentials, deploy keyloggers, extract browser passwords, and establish additional remote access channels.
SilkLurk
SilkLurk employs a similar modular architecture but uses DLL sideloading through legitimate NVIDIA and Realtek executables to load malicious components. Unlike OctLurk, SilkLurk derives its decryption routines from the victim computer name, making payload decryption specific to each compromised system. After establishing persistence through Windows services, the malware injects itself into memory, exchanges encrypted session keys with its C2 infrastructure, and receives additional plugins for in-memory execution. Investigators observed SilkLurk searching network shares for sensitive documents, archiving stolen data with WinRAR and 7-Zip, and deploying PlugX as a secondary payload, demonstrating its role as both an access platform and a launcher for broader espionage activities.
LurkProxy
Researchers also identified LurkProxy, a specialized companion utility that shares much of OctLurk's architecture but functions primarily as a reverse proxy rather than a traditional backdoor. LurkProxy establishes encrypted communications with attacker-controlled infrastructure and forwards network traffic between compromised systems and remote C2 servers using a proprietary binary protocol. This capability enables operators to tunnel communications through infected hosts while further obscuring their infrastructure and operational activity.
Attribution
Kaspersky identified multiple technical artifacts linking OctLurk and SilkLurk to the same operator, including shared staging directories, overlapping victim infections, common deployment techniques, and the deployment of PlugX during observed intrusions. Based on these findings, researchers assess with medium confidence that the campaign is operated by a Chinese-speaking threat actor. However, they emphasize there is currently insufficient evidence to attribute the activity to any previously identified threat group.
Analyst Commentary
The OctLurk and SilkLurk campaign demonstrates how sophisticated espionage operators increasingly rely on layered intrusion frameworks rather than a single malware family. Victim-specific payload decryption, reflective loading, modular plugins, redundant persistence mechanisms, credential theft utilities, remote administration tools, and proxy capabilities create multiple opportunities for attackers to maintain access even if one component is identified and removed. This reinforces the importance of behavioral detection, credential monitoring, and visibility across the entire intrusion lifecycle rather than relying exclusively on static malware signatures.
The victimology observed in this campaign aligns with organizations responsible for governance, diplomacy, law enforcement, logistics, research, and public services. Such targeting is consistent with China’s long-term strategic intelligence collection priorities focused on regional stability, government decision-making, and critical infrastructure awareness.
PolySwarm's crowdsourced threat intelligence platform helps defenders detect emerging and previously unseen malware by combining verdicts from dozens of security engines with rich contextual threat intelligence. This layered approach enables analysts to validate suspicious files more quickly, uncover low-prevalence threats, and accelerate investigations into sophisticated intrusion campaigns, improving detection confidence and reducing response times for security teams.
IOCs
PolySwarm has a sample of OctLurk.
9ea2f55c1c91d04820f5082cf113c73c6320b157baa98d69654117cfc8458296
Click here to view all samples of OctLurk in our PolySwarm portal.
Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.
Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.