Suspected Chinese-Speaking Hackers Target Central Asian Governments with OctLurk and SilkLurk

Cyber Espionage OctLurk/SilkLurk PlugX Activity Credential Theft Living-off-the-Land
Overview
Security researchers identified an ongoing cyber-espionage campaign attributed to a suspected Chinese-speaking threat actor active since January 2025. The operation uses newly identified malware families OctLurk and SilkLurk, alongside tooling such as LurkProxy and PlugX, to maintain long-term access, steal credentials, harvest sensitive government information, and exfiltrate confidential data while minimizing detection.
Technical Specifications
| Attribute | Details |
|---|---|
| Campaign Type | Government-focused cyber-espionage |
| Suspected Actor Profile | Chinese-speaking threat operator set |
| Primary Malware | OctLurk and SilkLurk memory-resident backdoors |
| Auxiliary Tooling | LurkProxy for proxy communications; PlugX RAT in selected intrusions |
| Credential Access Methods | Windows password hash harvesting with Impacket; browser credential theft; keylogging |
| Lateral Movement | SMB share abuse and internal reconnaissance across reachable hosts |
| Data Preparation | Collection and archiving using WinRAR or 7-Zip prior to exfiltration |
| Evasion Approach | Heavy Living-off-the-Land usage (PowerShell, CMD, native Windows utilities) |
| Infrastructure Clue | Observed overlap with previously reported SilentRaid campaign infrastructure |
Affected Products
- Central Asian government networks and administrative systems
- Windows enterprise endpoints and domain environments vulnerable to credential theft
- Organizations with weak lateral-movement controls on SMB and privileged accounts
- Public-sector infrastructure lacking detection for LotL and memory-resident backdoor behavior
Attack Scenario
- Attackers gain initial access to a target organization (initial vector not publicly disclosed).
- OctLurk and/or SilkLurk is deployed to establish stealthy persistence.
- The attackers collect system data, browser credentials, and password hashes.
- They perform internal reconnaissance and move laterally through SMB shares.
- Sensitive government files are identified and staged.
- Collected data is archived with legitimate compression tools.
- Archive bundles are exfiltrated to attacker-controlled infrastructure.
- Long-term access is maintained through PlugX and supporting malware components.
Impact Assessment
- Persistent unauthorized access can alter administrative workflows and trust boundaries
- LotL tradecraft complicates containment and increases chance of repeated reinfection
- Multi-tool persistence increases attacker resilience inside compromised networks
- Confidential government documents and internal records can be exfiltrated
- Credential theft enables sustained access and expansion into additional systems
- Keylogging and browser theft expose user and administrative secrets at scale
- Ongoing espionage operations may degrade service reliability during response actions
- Broad credential resets and host remediation can interrupt government operations
- Follow-on activity may increase risk of disruptive attacks against critical systems
Mitigation Strategies
Immediate Actions
- Deploy and tune EDR across government and high-value endpoint segments
- Enable PowerShell, command-line, and process auditing with centralized retention
- Investigate and contain suspicious PlugX, OctLurk, SilkLurk, and LurkProxy indicators
Short-term Measures
- Monitor SMB and administrative share access for anomalous lateral movement patterns
- Restrict privileged account usage and enforce least privilege boundaries
- Rotate administrator and service credentials on a recurring emergency cycle
Monitoring & Detection
- Detect abnormal archive creation patterns involving WinRAR/7-Zip in sensitive hosts
- Alert on DLL sideloading behavior and known PlugX loading chains
- Hunt for Living-off-the-Land execution chains tied to credential access and exfiltration staging
Long-term Solutions
- Segment sensitive government systems and isolate critical administrative domains
- Establish recurring threat-hunting missions focused on memory-resident backdoors
- Integrate intelligence mapping for SilentRaid-linked infrastructure and related actor clusters
Resources and References
Public Reporting
Last Updated: August 2, 2026