Technology

Kaspersky finds OctLurk and SilkLurk in attacks on Uzbek organizations

The researchers assess with medium confidence that one Chinese-speaking operator controls both malware families.

Kaspersky virus laboratory staff working at computer stations

Kaspersky researchers identified the OctLurk and SilkLurk backdoors in attacks on government organizations primarily in Central Asia, according to the company’s report.

The attacks have been tracked since January 2025. Identified victims are located in Uzbekistan, Kazakhstan, Kyrgyzstan, Tajikistan, Afghanistan and Syria.

The targeted organizations operate in healthcare, research, government offices, logistics, law enforcement, urban planning, facilities management and education.

OctLurk and SilkLurk can download additional modules to launch command shells, interact with files, scan networks, dump credentials, collect emails, log keystrokes, steal browser passwords and provide remote access.

Kaspersky assesses with medium confidence that one Chinese-speaking operator controls both backdoors. The researchers could not attribute the activity to any known threat group.

Marat AkhmetovРедактор