Memory-only backdoors OctLurk and SilkLurk stalk Central Asia

Kaspersky ties two memory-resident backdoors to government network intrusions across Central Asia.

CSBadmin
2 Min Read

Kaspersky researchers have uncovered a campaign by suspected Chinese-speaking attackers who have been compromising government networks across Central Asia since January 2025 using two memory-resident backdoors.

The attackers, tracked through malware called OctLurk and SilkLurk plus a proxy utility named LurkProxy, have hit organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and the Syrian Arab Republic. Targets span healthcare, research, foreign ministries, logistics, law enforcement, urban planning and public education, according to Kaspersky’s Securelist analysis.

OctLurk is injected into memory by a loader and can pull plugins that launch command shells, perform file operations, grab screenshots, dump credentials, keylog, steal browser passwords and collect email. Operators used its command shell to harvest password hashes from domain controllers with Impacket’s secretsdump, dropped a keylogger disguised as AnyDesk, established remote access with the Pandora RC agent and scanned networks with Fscan.

SilkLurk launches through a DLL side-loading chain, connects to a command-and-control server and can receive additional plugins. Post-compromise activity includes staging confidential documents, archiving them with WinRAR or 7-Zip, and dropping the well-known PlugX backdoor used by Chinese groups. LurkProxy routes traffic through SOCKS5 or transparent proxy modes.

Infrastructure overlaps with the earlier SilentRaid implant campaign suggest the operators reuse servers across separate operations, Kaspersky said. The backdoors live almost entirely in memory, leaving just a small loader on disk that ties payload decoding to machine specifics such as the drive serial number or computer name, a design that slows reverse engineering and automated detection.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.