Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
Summary
A Chinese-speaking threat actor has been targeting government organizations in Central Asian countries and Syria since January 2025. The attacks utilize previously unknown malware families dubbed OctLurk and SilkLurk, with the victims spanning healthcare, research, and government sectors.
IFF Assessment
The discovery of new malware and targeted attacks against government entities indicates a growing and sophisticated threat landscape, which is bad news for defenders.
Defender Context
Defenders should be aware of sophisticated, nation-state-backed threat actors targeting critical infrastructure and government entities, especially in geopolitical hotspots. The use of novel malware families like OctLurk and SilkLurk highlights the need for robust threat intelligence and advanced detection capabilities to identify and mitigate these evolving attacks.