Kaspersky's Global Research and Analysis Team (GReAT) has discovered an ongoing cyber espionage campaign targeting government, healthcare and research organizations across Central Asia and Syria. Active since January 2025, the campaign relies on highly customized malware that decrypts its payload only on the specific machine of an intended victim, making automated detection and analysis exceptionally difficult.
The threat actor operates two backdoors, which the researchers named OctLurk and SilkLurk, through a multi-plugin framework designed to evade security measures. Security tools often test suspicious files by opening them in a safe, isolated environment to see what they do, and these programs defeat that check. Before running, each one looks for a specific detail of its intended host — the serial number of the hard drive, or the computer's name — and uses it as the key to unscramble itself. Anywhere else, the file stays scrambled and reveals nothing.
Once inside a network, the attackers add tools as needed rather than installing everything at once. Kaspersky GReAT found that the deployed plugins are designed to take a command shell, perform file system activity and synthesize keyboard and mouse events. In addition to the plugins, they deployed tools to record keystrokes, copy saved passwords out of web browsers, read email, take screenshots and collect password data from the servers that manage employee logins. The tools also allow the operators to search shared network drives for confidential documents and package what they find using ordinary file compression software.
In addition to sophisticated obfuscation, the operators establish redundant access channels to ensure persistence. Kaspersky tracked the deployment of the well-known PlugX Remote Access Trojan (RAT) and legitimate remote monitoring software to maintain control even if the primary infection vector is neutralized. The researchers identified victims in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The compromised entities span government ministries, law enforcement agencies, logistics providers and urban planning facilities.
While Kaspersky cannot formally attribute the campaign to a known advanced persistent threat (APT) group, the use of the PlugX Trojan and specific infrastructure patterns indicate with medium confidence that the operators are Chinese-speaking.
"Most malware is written once and sent to thousands of targets, which is what makes it easy to catch. Here the attackers gave up that scale on purpose. Preparing a separate build for every victim takes real effort, and it tells you they were more concerned with staying hidden inside a small number of organizations than infecting a lot of them," said Saurabh Sharma, lead security researcher at Kaspersky GReAT.
Kaspersky security solutions detect the malware described here. The full technical analysis is available on Securelist.
To protect your organization from targeted attacks and advanced espionage campaigns, Kaspersky experts recommend:
- Providing your security team with clear and relevant intelligence. The Kaspersky Threat Intelligence Portal ensures easy interaction with one of the world’s largest cybersecurity knowledge bases, delivering exclusive reports, geo-filtering, and actionable insights in a single click. Equipping defenders with up-to-date data allows them to proactively identify and block campaigns like OctLurk and SilkLurk.
- Deploying enterprise-grade endpoint security. Organizations of any size and industry can enable real-time protection, threat visibility, investigation and response capabilities of EDR and XDR with solutions from the Kaspersky Next product line. Depending on your current needs and available resources, you can choose the most relevant product tier and easily migrate to another one if your cybersecurity requirements are changing.
- Implementing a managed security service. Augment your existing security controls with human-led detection from Kaspersky Managed Detection and Response (MDR) and receive comprehensive and detailed analysis of security incidents with Kaspersky Incident Response. These services offer 24/7 monitoring and cover the entire incident management cycle – from threat identification to continuous protection and remediation.
- Protecting critical infrastructure and credentials. In this campaign, attackers specifically targeted domain controllers to harvest employee passwords. Ensure strict access controls, rotate administrative credentials regularly and limit the number of accounts with the privileges required to create remote scheduled tasks or Windows services.
About the Global Research & Analysis Team
Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.