Executive Summary
Since January 2025, a Chinese-speaking threat actor has been conducting cyber attacks against government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These attacks have targeted sectors such as healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement agencies, urban planning, and public education. The attackers employ two new obfuscated backdoors, OctLurk and SilkLurk, along with a specialized utility called LurkProxy to proxy network traffic. These tools enable a range of malicious activities, including command execution, file operations, credential dumping, keylogging, and remote access.
The use of sophisticated backdoors and proxy tools in these attacks highlights an evolving threat landscape where state-sponsored actors develop and deploy advanced malware to achieve persistent access and data exfiltration. Organizations in the targeted regions should enhance their cybersecurity measures to detect and mitigate such threats.
Why This Matters Now
The emergence of OctLurk and SilkLurk backdoors signifies a shift towards more sophisticated cyber espionage tools targeting critical government sectors in Central Asia. This development underscores the urgent need for enhanced cybersecurity defenses to protect sensitive information and maintain national security.
Attack Path Analysis
The attackers initiated the campaign by exploiting vulnerabilities in public-facing government applications to gain initial access. They then escalated privileges by creating or modifying system processes to establish persistence. Utilizing DLL side-loading techniques, they moved laterally within the network to access additional systems. For command and control, they employed legitimate administrative tools to maintain covert communication channels. Sensitive data was exfiltrated by funneling it to legitimate cloud services. The impact included unauthorized access to confidential government information, leading to potential espionage and data breaches.
Kill Chain Progression
Initial Compromise
Description
Exploited vulnerabilities in public-facing government applications to gain initial access.
Related CVEs
CVE-2018-7600
CVSS 9.8A remote code execution vulnerability in Drupal Core allows unauthenticated attackers to execute arbitrary code.
Affected Products:
Drupal Drupal Core – < 7.58, < 8.3.9, < 8.4.6, < 8.5.1
Exploit Status:
exploited in the wildCVE-2018-7602
CVSS 9.8A remote code execution vulnerability in Drupal Core allows attackers to execute arbitrary code after successful exploitation of another vulnerability.
Affected Products:
Drupal Drupal Core – < 7.59, < 8.3.9, < 8.4.6, < 8.5.3
Exploit Status:
exploited in the wildCVE-2024-27956
CVSS 9.8A vulnerability in the WP-Automatic WordPress plugin allows attackers to execute arbitrary code via crafted input.
Affected Products:
WP-Automatic WP-Automatic Plugin – < 3.53.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Acquire Infrastructure: Domains
Acquire Infrastructure: Web Services
Command and Scripting Interpreter: PowerShell
Application Layer Protocol: Web Protocols
Archive Collected Data: Archive via Utility
Create Account: Domain Account
Abuse Elevation Control Mechanism: Bypass User Account Control
Account Discovery: Local Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Incident Handling
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary target of Chinese APT using OctLurk/SilkLurk against Central Asian governments requires enhanced zero trust segmentation and encrypted traffic controls.
Health Care / Life Sciences
Healthcare organizations in targeted regions face APT threats requiring HIPAA-compliant east-west traffic security and anomaly detection for lateral movement prevention.
Research Industry
Research institutions targeted by sophisticated APT need multicloud visibility controls and egress security to prevent intellectual property exfiltration via encrypted channels.
Telecommunications
Critical infrastructure sector vulnerable to APT lateral movement requiring enhanced threat detection and secure hybrid connectivity for encrypted private circuit protection.
Sources
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkhttps://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.htmlVerified
- ShadowSilk Data Exfiltration Attack | Outbreak Alert | FortiGuard Labshttps://www.fortiguard.com/outbreak-alert/shadowsilk-data-exfiltrationVerified
- ShadowSilk APT: Cross-Border Espionage Targeting Central Asia | Group-IBhttps://www.group-ib.com/masked-actors/shadowsilk/Verified
- Silent Lynx APT Group: A New Espionage Threat Targeting Central Asiahttps://securityonline.info/silent-lynx-apt-group-a-new-espionage-threat-targeting-central-asia/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit vulnerabilities, escalate privileges, move laterally, establish covert channels, and exfiltrate data, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in public-facing applications would likely be constrained, reducing the chances of initial access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and establish persistence would likely be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network would likely be constrained, reducing the reachability to additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain covert communication channels would likely be constrained, reducing the effectiveness of command and control.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external services would likely be constrained, reducing data loss.
The attacker's ability to access and exploit confidential information would likely be constrained, reducing the potential impact of espionage and data breaches.
Impact at a Glance
Affected Business Functions
- Government Communications
- Public Administration
- Healthcare Services
Estimated downtime: 14 days
Estimated loss: $5,000,000
Confidential government documents, sensitive healthcare records, and diplomatic communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows, preventing unauthorized lateral movement.
- • Utilize Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration to unauthorized destinations.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch public-facing applications to mitigate known vulnerabilities and reduce the risk of initial compromise.



