

Kaspersky's Global Research and Analysis Team (GReAT) has discovered an ongoing cyber espionage campaign targeting government, healthcare and research organizations across Central Asia and Syria. Active since January 2025, the campaign relies on highly customized malware that decrypts its payload only on the specific machine of an intended victim, making automated detection and analysis exceptionally difficult.
The threat actor operates two backdoors, which the researchers named OctLurk and SilkLurk, through a multi-plugin framework designed to evade security measures. Security tools often test suspicious files by opening them in a safe, isolated environment to see what they do, and these programs defeat that check. Before running, each one looks for a specific detail of its intended host — the serial number of the hard drive, or the computer's name — and uses it as the key to unscramble itself. Anywhere else, the file stays scrambled and reveals nothing.
Once inside a network, the attackers add tools as needed rather than installing everything at once. Kaspersky GReAT found that the deployed plugins are designed to take a command shell, perform file system activity and synthesize keyboard and mouse events. In addition to the plugins, they deployed tools to record keystrokes, copy saved passwords out of web browsers, read email, take screenshots and collect password data from the servers that manage employee logins. The tools also allow the operators to search shared network drives for confidential documents and package what they find using ordinary file compression software.
In addition to sophisticated obfuscation, the operators establish redundant access channels to ensure persistence. Kaspersky tracked the deployment of the well-known PlugX Remote Access Trojan (RAT) and legitimate remote monitoring software to maintain control even if the primary infection vector is neutralized. The researchers identified victims in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The compromised entities span government ministries, law enforcement agencies, logistics providers and urban planning facilities.
While Kaspersky cannot formally attribute the campaign to a known advanced persistent threat (APT) group, the use of the PlugX Trojan and specific infrastructure patterns indicate with medium confidence that the operators are Chinese-speaking.
"Most malware is written once and sent to thousands of targets, which is what makes it easy to catch. Here the attackers gave up that scale on purpose. Preparing a separate build for every victim takes real effort, and it tells you they were more concerned with staying hidden inside a small number of organizations than infecting a lot of them," said Saurabh Sharma, lead security researcher at Kaspersky GReAT.
𝐒𝐭𝐚𝐲 𝐢𝐧𝐟𝐨𝐫𝐦𝐞𝐝 𝐰𝐢𝐭𝐡 𝐨𝐮𝐫 𝐥𝐚𝐭𝐞𝐬𝐭 𝐮𝐩𝐝𝐚𝐭𝐞𝐬 𝐛𝐲 𝐣𝐨𝐢𝐧𝐢𝐧𝐠 𝐭𝐡𝐞 WhatsApp Channel now! 👈📲
𝑭𝒐𝒍𝒍𝒐𝒘 𝑶𝒖𝒓 𝑺𝒐𝒄𝒊𝒂𝒍 𝑴𝒆𝒅𝒊𝒂 𝑷𝒂𝒈𝒆𝐬 👉 Facebook, LinkedIn, Twitter, Instagram