OctLurk and SilkLurk Campaign Targeting Central Asian Governments
First seen Aug 1, 2026 · Updated Aug 1, 2026
A suspected Chinese-speaking threat actor has been conducting an espionage campaign since January 2025, primarily targeting government organizations in Central Asia and Afghanistan, as well as Syria. The campaign employs two custom malware families, OctLurk and SilkLurk, to establish persistent access for likely intelligence collection purposes.
Technical Analysis
The threat actor deploys two distinct malware toolsets, OctLurk and SilkLurk, likely used for initial access, persistence, and data exfiltration against government, healthcare, and research sector targets. Attribution to a Chinese-speaking actor suggests alignment with known regional cyber-espionage TTPs, though specific initial access vectors (phishing, exploited public-facing applications) were not fully detailed in available reporting. No CVEs have been publicly confirmed as part of this campaign at this time. Organizations in affected government sectors that operate AI-driven document processing, translation, or RAG pipelines for classified or sensitive data could see credentials or API keys harvested by this malware repurposed to access or manipulate agent-connected systems, extending the espionage impact beyond traditional data theft.
Affected Systems
Government office networks, healthcare sector IT systems, and research institution infrastructure in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria
Indicators of Compromise
- Malware family: OctLurk
- Malware family: SilkLurk
- (No specific hashes, IPs, or domains disclosed in available reporting)
Remediation Steps
- 1
Enhance Network Monitoring
Deploy network detection tools to identify anomalous outbound traffic patterns consistent with C2 beaconing associated with OctLurk/SilkLurk.
- 2
Endpoint Detection and Response
Ensure EDR solutions are updated with the latest threat intelligence signatures for these malware families as they become available.
- 3
Credential Hygiene and Rotation
Rotate credentials and API keys for any systems, including AI agent or RAG pipeline integrations, that may have been exposed to compromised endpoints.
- 4
Phishing Awareness Training
Conduct targeted training for government and healthcare staff on spear-phishing recognition, a common initial access vector for APT campaigns.
- 5
Network Segmentation
Segment sensitive government and research networks from general administrative systems to limit lateral movement.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.