#OctLurk
-Far-right image board builds AI doxing tool
-New NullReceiver C2 technique
-New Fuyao ad fraud botnet
-New OctLurk and SilkLurk malware
-Storm-1516's Armenia campaign
-KindaRails2Shell vulnerability
-RufRoot vulnerability
-Apple introduces bug reporting cool-offs
-WaterISAC denounces leak
August 3, 2026 at 7:58 AM
📢🪟⚠️ 2 new Windows backdoors, OctLurk and SilkLurk, have been targeting government systems in 6 countries, stealing credentials, logging keystrokes, collecting files, and enabling remote access.

Listen/Read: hackread.com/octlurk-silk...

#CyberSecurity #Malware #Windows #OctLurk #SilkLurk
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
hackread.com
August 5, 2026 at 7:25 PM
The Hidden Network Behind OctLurk: How Shared Malware Infrastructure May Be Linking Cyber Espionage to Kazakhstan’s Critical Systems + Video

Introduction: A Digital Trail That Reaches Beyond One Campaign Cyber-espionage operations rarely exist in complete isolation. Behind every malicious implant,…
The Hidden Network Behind OctLurk: How Shared Malware Infrastructure May Be Linking Cyber Espionage to Kazakhstan’s Critical Systems + Video
Introduction: A Digital Trail That Reaches Beyond One Campaign Cyber-espionage operations rarely exist in complete isolation. Behind every malicious implant, encrypted command channel, and carefully selected victim is an infrastructure layer that can quietly connect campaigns that appear unrelated on the surface. Security researchers have now uncovered one such connection involving the OctLurk malware framework, its companion backdoor SilkLurk, and infrastructure previously associated with TrustFall, a Linux-focused remote-access malware also tracked as MystRodX and SilentRaid.
undercodenews.com
July 31, 2026 at 7:38 AM
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries

Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
#hackernews #news
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
hackread.com
August 6, 2026 at 7:42 PM
Chinese-speaking hackers are targeting Central Asian governments with OctLurk and SilkLurk. Another day, another batch of nation-state intrusions.

#OctLurk #SilkLurk
August 1, 2026 at 11:51 AM
Two backdoors – OctLurk and SilkLurk – have been used in attacks against government organizations primarily in Central Asia since January 2025.The loaders are customized for each victim. No attribution so far. Deep dive into the technical analysis:
OctLurk and SilkLurk: new Backdoors in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
kas.pr
July 31, 2026 at 2:32 PM
Target-Locked Malware Narrows Central Asia Cyber Espionage Risk

Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare

#Cybersecurity #HealthTech

Link card below.
Target-Locked Malware Narrows Central Asia Cyber Espionage Risk
Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia
stechtimes.com
August 8, 2026 at 12:06 AM
New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers
New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers
Government networks in Central Asia have been hit by two custom-built backdoors that give intruders deep control over infected computers. Known as OctLurk and SilkLurk, the tools can record keystrokes, collect browser passwords, steal email, and run commands remotely. The campaign has been active since January 2025 and has affected organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria. Victims include ministries, law enforcement agencies, healthcare bodies, research institutions, logistics organizations, schools, and urban planning offices. Securelist said in a report shared with Cyber Security News (CSN) that both malware families are used by the same likely Chinese-speaking threat actor, although the operation has not been tied to a known group. The intrusion shows how a determined espionage team can turn one compromised machine into a doorway to a wider government network. The attackers used stolen administrator credentials, scheduled tasks, malicious services, and additional tools to maintain access and gather sensitive information. New Backdoors Let Hackers Keylog, Steal Passwords OctLurk is built to stay hidden while giving its operators a wide range of options after a system is breached. Its loader is customized for each victim and uses machine-specific information to unlock the final payload, which makes automated analysis and detection harder. Once active, OctLurk can pull additional plugins directly into memory instead of relying on many visible files. SilkLurk loader (Source – Securelist) Those plugins let attackers browse and copy files, open command shells, capture screenshots, read clipboard contents, scan networks, and simulate keyboard and mouse actions. The operators also used a keylogger and a browser password recovery utility to capture credentials from compromised systems. The keylogger saved keystrokes and clipboard data locally, while the browser tool targeted stored sign-in data from Chrome and Firefox. This combination creates a serious risk for public-sector organizations because a single employee account can lead to more valuable systems. The attackers also used a password-dumping tool against domain controllers, seeking credentials that could help them move across the network. Their use of scheduled tasks is especially concerning because the tasks ran with high-level system privileges and were named to look ordinary. Similar  scheduled task persistence techniques  are widely used to help attackers keep access after a restart or an initial cleanup effort. OctLurk also supported a proxy component that could relay traffic through a compromised device. That capability can help operators reach internal systems that are not directly exposed to the internet, reducing the chance that their activity is immediately noticed. SilkLurk Expands Espionage SilkLurk uses a different loading method, hiding behind legitimate-looking Windows programs and malicious DLL files. It verifies the host program, decrypts its payload using the victim computer name, injects it into memory, and creates a service to remain active. Pandora FMS agents (Source – Securelist) After gaining access, the attackers used SilkLurk to search shared network drives for confidential documents. They then compressed collected files with archiving utilities, a common step before data is moved out of an organization. The campaign also deployed PlugX, a long-running remote-access trojan associated with several Chinese-linked operations. Readers tracking related activity can review  Chinese APT PlugX campaigns , which illustrate how modular backdoors can support espionage through file theft, screenshots, keystroke capture, and remote commands. Government defenders should review administrator account use, investigate unfamiliar services and scheduled tasks, and monitor for unusual access to domain controllers, browser credential stores, and shared drives. Teams should also check endpoint and network telemetry for the indicators below, rotate exposed credentials, and isolate affected hosts during incident response. The campaign underlines the value of watching behavior rather than depending only on file-based detection. Organizations that regularly review task creation, service installation, remote logons, and suspicious internal scanning have a better chance of finding an intrusion before it becomes a broader compromise. Indicators of Compromise (IoCs):- Type Indicator Description Domain dns.ssentialserv[.]xyz LurkProxy command-and-control domain IP address 154.196.162[.]76 LurkProxy command-and-control server Domain dns.multitoconference[.]com OctLurk command-and-control domain Domain gycudore.kozow[.]com PlugX command-and-control domain Domain ctyuhjerf.kozow[.]com SilkLurk command-and-control domain IP address 64.7.198[.]130 PlugX command-and-control address MD5 6ecf84fb18f6747ed08d7598364d853a OctLurk deployment batch script MD5 082d49ef9f14e6811d68c7e0e82e5069 OctLurk loader DLL MD5 b874123a80fc4f40e06872b9cb54ebc6 LurkProxy deployment batch script MD5 45cf5916fab4272a1313c26e67aa9220 Victim-fingerprinting batch script MD5 4e6d5c4770d5a822d7fcce6a74f7ad73 Victim-fingerprinting batch script MD5 32a5985543433a4f60da2fafd873b927 Credential-dumping executable MD5 2a571f6cee42a17d873f4c942649813f Keylogger executable MD5 37dc84e4bcad92fa28f1e7778d088283 Browser password decryptor MD5 5e26df131ff0a679a0a2699b723b46e3 Remote-control agent deployment script MD5 cf903e4a1629aa0582fd0363b5786676 Fscan network-scanning tool MD5 3c9a1ba8e0c7475706adc6376e9d7b7c PlugX dropper MD5 62944e26b36b1dcace429ae26ba66164 PlugX sideloaded executable MD5 ef59aad625eebda8650aec5820d6ce69 PlugX loader DLL MD5 be4731c09734da2e8eb6814a9c82f266 SilkLurk loader DLL MD5 7c2f64461bb519c6cbf1fc687675514c OctLurk loader DLL MD5 f4578e869a735cfad691f927bae3e638 OctLurk loader DLL MD5 2f18472866f38c1e1c2c5c14b9a6ab56 SilkLurk loader DLL Filename oleasapi.dll OctLurk loader DLL Filename msbasesysdc.dll LurkProxy loader DLL Filename Adobe.exe Credential-dumping utility Filename OneDrive.dat SilkLurk payload file Filename nvml.dll SilkLurk loader DLL Filename vulkan-1.dll SilkLurk loader DLL Filename RtkSmbusLoc.dll SilkLurk loader DLL Filename RtkNGUI64Loc.dll SilkLurk loader DLL Filename C.dll PlugX loader DLL Filename C.dll.res PlugX payload file Filename GoogleUpDate Malicious scheduled task name Filename AnyDesk Keylogger scheduled task name Filename NgcCIntSvc OctLurk malicious service Filename Cusrxsrv LurkProxy malicious service Filename RmSs SilkLurk persistence service Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Building Resilience Against Phishing & Malware and  Analyze  it in a safe environment –  Power your SOC with ANY.RUN The post New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers appeared first on Cyber Security News .
cybersecuritynews.com
July 31, 2026 at 7:16 AM
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries: hackread.com/octlurk-silk...
hackread.com
August 10, 2026 at 12:39 AM
Chinese-linked hackers deploying new malware families to hit Central Asian governments. Security teams should prioritize detection of OctLurk and SilkLurk variants in their…

https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html

#cybersecurity #infosec
August 8, 2026 at 7:00 PM
OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima
il blog: insicurezzadigitale.com/octlurk-e-si...

#cybersecurity #apt #backdoor #cina #cyberspionaggio #infosec #kaspersky
August 7, 2026 at 9:12 AM
# **OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima**

@informatica
Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul […]
Original post on poliverso.org
poliverso.org
August 6, 2026 at 8:14 PM
Kaspersky GReAT uncovered OctLurk and SilkLurk, two new memory-resident backdoors targeting Central Asian governments since January 2025.

#OctLurk #SilkLurk #CentralAsia #CyberEspionage #APT
OctLurk and SilkLurk Backdoors Hit Central Asian Government Networks
At a glance
securityonline.info
August 5, 2026 at 8:12 AM
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
securelist.com
August 4, 2026 at 2:09 PM
OctLurk関連ハッカー集団、中東政府機関にBINDCLOAKバックドアを展開

今回、BINDCLOAKと呼ばれる、これまで報告されていなかったモジュール型バックドアの実態を明らかにする2部構成の技術分析レポートのうち、第2部が公開されました。BINDCLOAKは東アジア系とされる脅威アクター「OctLurk」によって、中東の政府機関を標的に展開されていました。 今回の公開は、同一の多段階侵入チ...
OctLurk関連ハッカー集団、中東政府機関にBINDCLOAKバックドアを展開
今回、BINDCLOAKと呼ばれる、これまで報告されていなかったモジュール型バックドアの実態を明らかにする2部構成の技術分析レポートのうち、第2部が公開されました。BINDCLOAKは東アジア系とされる脅威アクター「OctLurk」によって、中東の政府機関を標的に展開されていました。 今回の公開は、同一の多段階侵入チ
blackhatnews.tokyo
August 4, 2026 at 7:35 AM
Open-source supply chains are under pressure as attackers target PyPI, npm, Docker, and GitHub Actions. Active SonicWall exploitation, N-able N-central takeovers, and new tools like AtlasRAT also surface in phishing campaigns. #PyPI #SonicWall #Nable
Cybersecurity News | Daily Recap [03 Aug 2026]
Daily Recap, Cyber threat research points to a rise in open-source and developer-supply-chain compromises across PyPI, npm, Docker, and GitHub Actions, while AI is being both leveraged by attackers and targeted in ongoing operations. Reports also flag active exploitation of SonicWall vulnerabilities in ransomware activity, N-able N-central server takeovers after an incomplete fix, and new backdoor tooling including AtlasRAT, OctLurk, SilkLurk, and GoGRPC in phishing and helpdesk-vishing campaigns. #PyPI #npm #Docker #GitHubActions #SonicWall #N-able #N-central #AtlasRAT #OctLurk #SilkLurk #GoGRPC #BTMOB #BrinksHome #WiFi #COLDCARD #Bitcoin
www.hendryadrian.com
August 4, 2026 at 5:00 PM
Zscaler ThreatLabz presents the second part of a technical analysis of new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. This part looks into a new modular stage 3 backdoor: BINDCLOAK, a variant of OctLurk. www.zscaler.com/blogs/securi...
August 4, 2026 at 7:42 AM
Zscaler reports BINDCLOAK, a new 64-bit Windows backdoor linked with high confidence to OctLurk, delivered in a multi-stage campaign against government entities in the Middle East. #MiddleEast #OctLurk #BINDCLOAK
Targeted Attack on Government Entities in the Middle East | Part 2
Zscaler details BINDCLOAK, a new 64-bit modular Windows backdoor that appears to be a variant of OctLurk and was delivered through MIXEDKEY in a multi-stage attack against government entities in the Middle East. The report also links the campaign to shared C2 infrastructure, reflective DLL loading, token abuse, and encrypted TLS-over-TCP communications used by the same threat actor behind OctLurk. #BINDCLOAK #OctLurk #MIXEDKEY #TELESHIM #cert.hypersnet.com #about.blsouqs.com #ftabnews.com
www.hendryadrian.com
August 3, 2026 at 9:30 PM
新型バックドア「BINDCLOAK」、Windowsトークンを窃取しマルウェアをメモリ内に直接読み込み

セキュリティ研究者らは、中東の政府機関を標的とする東アジア関連の脅威アクターと結びつく新たなモジュール型Windowsバックドア「BINDCLOAK」を発見しました。 このマルウェアは、これまで中央アジアの標的への攻撃で確認されていたバックドア「OctLurk」の亜種とみられています。 ThreatLabzは、多段階
新型バックドア「BINDCLOAK」、Windowsトークンを窃取しマルウェアをメモリ内に直接読み込み
セキュリティ研究者らは、中東の政府機関を標的とする東アジア関連の脅威アクターと結びつく新たなモジュール型Windowsバックドア「BINDCLOAK」を発見しました。 このマルウェアは、これまで中央アジアの標的への攻撃で確認されていたバックドア「OctLurk」の亜種とみられています。 ThreatLabzは、多段階
blackhatnews.tokyo
August 4, 2026 at 7:36 AM