Skip to main content

Kaspersky uncovers victim-tailored backdoors in Central Asia targeting government, healthcare and research

July 30, 2026

Kaspersky's Global Research and Analysis Team (GReAT) has discovered an ongoing cyber espionage campaign targeting government, healthcare and research organizations across Central Asia and Syria. Active since January 2025, the campaign relies on highly customized malware that decrypts its payload only on the specific machine of an intended victim, making automated detection and analysis exceptionally difficult.

The threat actor operates two backdoors, which the researchers named OctLurk and SilkLurk, through a multi-plugin framework designed to evade security measures. Security tools often test suspicious files by opening them in a safe, isolated environment to see what they do, and these programs defeat that check. Before running, each one looks for a specific detail of its intended host — the serial number of the hard drive, or the computer's name — and uses it as the key to unscramble itself. Anywhere else, the file stays scrambled and reveals nothing.

Once inside a network, the attackers add tools as needed rather than installing everything at once. Kaspersky GReAT found that the deployed plugins are designed to take a command shell, perform file system activity and synthesize keyboard and mouse events. In addition to the plugins, they deployed tools to record keystrokes, copy saved passwords out of web browsers, read email, take screenshots and collect password data from the servers that manage employee logins. The tools also allow the operators to search shared network drives for confidential documents and package what they find using ordinary file compression software.

In addition to sophisticated obfuscation, the operators establish redundant access channels to ensure persistence. Kaspersky tracked the deployment of the well-known PlugX Remote Access Trojan (RAT) and legitimate remote monitoring software to maintain control even if the primary infection vector is neutralized. The researchers identified victims in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The compromised entities span government ministries, law enforcement agencies, logistics providers and urban planning facilities.

While Kaspersky cannot formally attribute the campaign to a known advanced persistent threat (APT) group, the use of the PlugX Trojan and specific infrastructure patterns indicate with medium confidence that the operators are Chinese-speaking.

"Most malware is written once and sent to thousands of targets, which is what makes it easy to catch. Here the attackers gave up that scale on purpose. Preparing a separate build for every victim takes real effort, and it tells you they were more concerned with staying hidden inside a small number of organizations than infecting a lot of them," said Saurabh Sharma, lead security researcher at Kaspersky GReAT.

Kaspersky security solutions detect the malware described here. The full technical analysis is available on Securelist. 

To protect your organization from targeted attacks and advanced espionage campaigns, Kaspersky experts recommend:

  • Providing your security team with clear and relevant intelligence. The Kaspersky Threat Intelligence Portal ensures easy interaction with one of the world’s largest cybersecurity knowledge bases, delivering exclusive reports, geo-filtering, and actionable insights in a single click. Equipping defenders with up-to-date data allows them to proactively identify and block campaigns like OctLurk and SilkLurk. 
  • Deploying enterprise-grade endpoint security. Organizations of any size and industry can enable real-time protection, threat visibility, investigation and response capabilities of EDR and XDR with solutions from the Kaspersky Next product line. Depending on your current needs and available resources, you can choose the most relevant product tier and easily migrate to another one if your cybersecurity requirements are changing.
  • Implementing a managed security service. Augment your existing security controls with human-led detection from Kaspersky Managed Detection and Response (MDR) and receive comprehensive and detailed analysis of security incidents with Kaspersky Incident Response. These services offer 24/7 monitoring and cover the entire incident management cycle – from threat identification to continuous protection and remediation. 
  • Protecting critical infrastructure and credentials. In this campaign, attackers specifically targeted domain controllers to harvest employee passwords. Ensure strict access controls, rotate administrative credentials regularly and limit the number of accounts with the privileges required to create remote scheduled tasks or Windows services.

About the Global Research & Analysis Team

Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.

Kaspersky uncovers victim-tailored backdoors in Central Asia targeting government, healthcare and research

Kaspersky's Global Research and Analysis Team (GReAT) has discovered an ongoing cyber espionage campaign targeting government, healthcare and research organizations across Central Asia and Syria. Active since January 2025, the campaign relies on highly customized malware that decrypts its payload only on the specific machine of an intended victim, making automated detection and analysis exceptionally difficult.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases