highAPT

OctLurk and SilkLurk Campaign Targeting Central Asian Governments

First seen Aug 1, 2026 · Updated Aug 1, 2026

APTChina-nexusCentral-Asiagovernmentespionagemalwarebackdoor

A suspected Chinese-speaking threat actor has been conducting an espionage campaign since January 2025, primarily targeting government organizations in Central Asia and Afghanistan, as well as Syria. The campaign employs two custom malware families, OctLurk and SilkLurk, to establish persistent access for likely intelligence collection purposes.

Technical Analysis

The threat actor deploys two distinct malware toolsets, OctLurk and SilkLurk, likely used for initial access, persistence, and data exfiltration against government, healthcare, and research sector targets. Attribution to a Chinese-speaking actor suggests alignment with known regional cyber-espionage TTPs, though specific initial access vectors (phishing, exploited public-facing applications) were not fully detailed in available reporting. No CVEs have been publicly confirmed as part of this campaign at this time. Organizations in affected government sectors that operate AI-driven document processing, translation, or RAG pipelines for classified or sensitive data could see credentials or API keys harvested by this malware repurposed to access or manipulate agent-connected systems, extending the espionage impact beyond traditional data theft.

Affected Systems

Government office networks, healthcare sector IT systems, and research institution infrastructure in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria

Indicators of Compromise

  • Malware family: OctLurk
  • Malware family: SilkLurk
  • (No specific hashes, IPs, or domains disclosed in available reporting)

Remediation Steps

  1. 1

    Enhance Network Monitoring

    Deploy network detection tools to identify anomalous outbound traffic patterns consistent with C2 beaconing associated with OctLurk/SilkLurk.

  2. 2

    Endpoint Detection and Response

    Ensure EDR solutions are updated with the latest threat intelligence signatures for these malware families as they become available.

  3. 3

    Credential Hygiene and Rotation

    Rotate credentials and API keys for any systems, including AI agent or RAG pipeline integrations, that may have been exposed to compromised endpoints.

  4. 4

    Phishing Awareness Training

    Conduct targeted training for government and healthcare staff on spear-phishing recognition, a common initial access vector for APT campaigns.

  5. 5

    Network Segmentation

    Segment sensitive government and research networks from general administrative systems to limit lateral movement.

Industries Most Exposed

governmenthealthcareresearch

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.