A suspected Chinese-speaking threat actor has been linked to a sustained campaign of cyberattacks against government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, and Kazakhstan, according to reporting by The Hacker News. The source reporting also indicates the Syrian Arab Republic may be among the targeted states.
Active since January 2025, the campaign has deployed two custom malware families—OctLurk and SilkLurk—that leverage in-memory plugins and credential theft to compromise targets. Affected organizations span government offices, healthcare providers, and research institutions, sectors that handle sensitive administrative data, citizen records, and strategic research material.
Security researchers assessing the activity note that the use of two distinct malware families points to a mature, well-resourced operation rather than opportunistic crime. Dual-tooling of this kind often indicates specialized roles within the attack chain: one component may handle initial access or reconnaissance, while the other supports longer-term persistence, lateral movement, or data exfiltration. Such modular approaches are characteristic of advanced persistent threat groups that invest in purpose-built capabilities for prolonged intelligence collection.
Central Asia's geopolitical position adds weight to the findings. The region sits at the intersection of major trade corridors, energy routes, and competing strategic interests. Government networks there can offer valuable insight into policy decisions, security postures, and infrastructure planning—intelligence of clear value to a state-aligned operator.
For the wider IT and security community, the campaign underscores several persistent realities. The use of in-memory plugin architectures and custom credential-theft tooling demonstrates that well-funded actors continue to develop private capabilities designed to evade commodity detection signatures. Defenders relying solely on known-indicator blocklists may miss the early stages of similar intrusions. Meanwhile, many organizations in emerging or resource-constrained environments face structural challenges—limited security budgets, legacy systems, and thinner incident-response capacity—that make them attractive targets for long-running espionage.
The longevity of the campaign, spanning multiple countries and sectors for months, implies careful operational security and an ability to adapt to local network conditions. It also serves as a reminder that state-aligned groups frequently prioritize regions that receive less continuous public scrutiny from global threat-intelligence vendors, allowing campaigns to mature before wider disclosure.
Defensive takeaways remain consistent with established best practices, though they gain urgency in light of sophisticated dual-malware deployments. Network segmentation, rigorous monitoring of unusual outbound connections, timely patching of internet-facing services, and behavioral detection capable of spotting novel tooling all reduce the window of opportunity for such actors. Sharing anonymized indicators and tactics across regional CERTs and open-source intelligence communities can further raise the cost of reuse.
While attribution to a specific named group has not been publicly confirmed beyond the linguistic and targeting patterns described, the combination of custom dual malware, multi-country government focus, and multi-sector reach marks this as a notable espionage-oriented effort. As details continue to emerge, security teams responsible for public-sector or research networks—particularly those with any operational or supply-chain links to the affected region—have clear reason to review detection coverage for similar modular toolkits.
據《The Hacker News》報導,一個疑似以中文為母語的威脅行為者被指與一場針對主要位於中亞政府機構的持續網絡攻擊行動有關,目標包括阿富汗、吉爾吉斯、塔吉克、烏茲別克及哈薩克。該來源報導亦指出,阿拉伯敘利亞共和國可能為受攻擊國家之一。
該行動自2025年1月起活躍,部署了兩款名為OctLurk及SilkLurk的自訂惡意軟件家族,利用記憶體內插件及憑證竊取技術入侵目標。受影響組織涵蓋政府辦公室、醫療服務提供者及研究機構,這些行業處理敏感的行政數據、市民記錄及戰略研究資料。
評估此活動的安全研究人員指出,使用兩種不同惡意軟件家族,顯示這是一場成熟、資源充足的操作,而非機會主義犯罪。此類雙工具使用通常意味攻擊鏈中存在專業分工:一個組件可能負責初始入侵或偵察,另一個則支持長期持續存在、橫向移動或數據外洩。這種模塊化手法正是進階持續威脅組織的特徵,這些組織會投資開發專用工具以進行長期情報收集。
中亞的地緣政治位置增加了這些發現的重要性。該地區位於主要貿易通道、能源路線及相互競爭的戰略利益交匯處。當地的政府網絡能提供有關政策決定、安全態勢及基礎設施規劃的寶貴情報——這些情報對國家支持的行動者具有明確價值。
對更廣泛的IT及安全界而言,此行動突顯了幾個持續存在的現實。採用記憶體內插件架構及自訂憑證竊取工具,顯示資金充足的行為者持續開發專門設計用以規避通用檢測特徵的私有能力。僅依賴已知指標封鎖名單的防禦者,可能會錯過類似入侵的早期階段。同時,許多在新興或資源受限環境中的組織面臨結構性挑戰——有限的安全預算、舊式系統及較薄弱的事故響應能力——使它們成為長期間諜行動的理想目標。
此行動橫跨多個國家及行業維持數月的長時間運作,意味着謹慎的操作安全性及適應本地網絡條件的能力。這也提醒我們,國家支持的團體經常優先針對那些較少受到全球威脅情報供應商持續關注的地區,使行動能在更廣泛披露前成熟。
防禦要點與既定最佳實踐保持一致,但鑑於複雜的雙惡意軟件部署而變得更為緊迫。網絡分段、嚴格監控異常出站連接、及時修補面向互聯網的服務,以及能夠偵測新型工具的行為檢測,都能縮減此類行為者的可乘之機。在區域CERT及開源情報社群之間共享匿名指標和戰術,可進一步提高重複利用的成本。
儘管除了所述的語言和目標模式外,尚未公開確認具體命名團體的歸因,但雙自訂惡意軟件、多國政府目標及多範疇覆蓋的組合,標誌著這是一項顯著的間諜導向行動。隨著細節持續浮現,負責公共部門或研究網絡——特別是與受影響區域有任何運作或供應鏈聯繫——的安全團隊,有明確理由檢視其對類似模塊化工具組的偵測覆蓋範圍。
