The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

OctLurk and SilkLurk: Analysis of a Modular Cyber Espionage Framework

Aug 6, 2026, 2:14:03 PM / by The Hivemind posted in Threat Bulletin, PlugX, credential theft, cyber espionage, OctLurk, SilkLurk, LurkProxy, modular backdoor

0 Comments

Verticals Targeted: Government, Ministries of Foreign Affairs, Healthcare, Research, Logistics, Law Enforcement, Urban Planning and Facilities Management, Education
Regions Targeted: Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, Uzbekistan
Related Families: OctLurk, SilkLurk, LurkProxy, PlugX

Executive Summary

Industry researchers have identified a sophisticated cyber espionage campaign leveraging two previously undocumented malware families, OctLurk and SilkLurk, against government organizations and public-sector entities across Central Asia and the Middle East. Both modular backdoors employ victim-specific decryption, extensive obfuscation, and in-memory execution to evade detection while enabling credential theft, remote access, network reconnaissance, and plugin-based expansion. Researchers also identified a companion utility, LurkProxy, used to proxy attacker traffic.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts