OctLurk is a modular Windows backdoor used in a cyber-espionage campaign active since at least January 2025 against government and public-sector organizations in Central Asia and the Middle East. Confirmed victim countries include Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria, with affected sectors including foreign affairs, law enforcement, healthcare, logistics, research, urban planning, facilities management, education, and in later related activity, government and energy entities in the Middle East. Reporting assesses with medium confidence that the broader campaign is operated by a Chinese-speaking threat actor, although it has not been conclusively tied to a known intrusion set.
OctLurk is delivered through customized loader DLLs and is designed for stealth. Its loaders use victim-specific decryption material derived in part from host attributes such as the system drive serial number, then decrypt and inject the backdoor into memory. The malware is heavily obfuscated, primarily memory-resident, and supports reflective in-memory loading of additional plugins, reducing forensic artifacts on disk. Persistence has been observed through Windows services and scheduled tasks.
Once active, OctLurk gathers host information, establishes encrypted command-and-control communications, and can download plugins directly into memory. Documented plugin and operator-enabled functions include command shell access, filesystem management, screenshot capture, clipboard interaction, keyboard and mouse simulation, host and network reconnaissance, credential harvesting, browser password theft, keylogging, email collection, and broader remote administration. Intrusions involving OctLurk also showed rapid progression from reconnaissance to credential theft and lateral movement, including use of administrative credentials, password dumping, network scanning, and deployment of additional remote-access tooling.
OctLurk is closely linked to the companion malware SilkLurk and the proxy utility LurkProxy through overlapping victims, infrastructure, deployment patterns, and operational workflows. Separate research also assessed with high confidence that BINDCLOAK is a variant of OctLurk based on significant code similarities and shared command-and-control infrastructure, indicating continued evolution of the malware family and expansion of the associated espionage activity into the Middle East.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
On infected computers, OctLurk is installed through scheduled tasks and malicious Windows services after the attacker obtains administrative credentials.
OctLurk is a modular backdoor delivered through customized loader DLLs that establish persistence using Windows services and scheduled tasks.
This design allows the attackers to add capabilities as needed, including command execution...
On infected computers, OctLurk is installed through scheduled tasks and malicious Windows services after the attacker obtains administrative credentials.
On infected computers, OctLurk is installed through scheduled tasks and malicious Windows services after the attacker obtains administrative credentials.
OctLurk is a modular backdoor delivered through customized loader DLLs that establish persistence using Windows services and scheduled tasks.
During post-compromise activity, operators expanded their foothold using legitimate administration software alongside publicly available offensive tools, including Impacket's SecretsDump
including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation
operators used OctLurk to perform extensive host reconnaissance, collect event logs, harvest credentials, deploy keyloggers
During OctLurk infections, Kaspersky observed the attackers collecting system and network details before deploying tools such as Impacket’s secretsdump...
During observed intrusions, operators used OctLurk to perform extensive host reconnaissance
During post-compromise activity, operators expanded their foothold using legitimate administration software alongside publicly available offensive tools, including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX.
including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation
operators used OctLurk to perform extensive host reconnaissance, collect event logs, harvest credentials, deploy keyloggers
These plugins provide command shell access, filesystem management, screenshot capture, clipboard interaction
These components give the operator command-shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection and remote access. They also installed Pandora remote-control agents and connected directly to email servers using account credentials.
Once active, OctLurk collects host information, establishes encrypted communications with its C2 infrastructure
BINDCLOAK communicates with its command server through TLS over TCP, using a custom message-routing system.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor delivered through customized loader DLLs that establishes persistence via Windows services and scheduled tasks, decrypts payloads using victim-specific attributes, injects itself into memory, communicates with C2, and loads plugins for remote administration, reconnaissance, credential theft, and surveillance.
A previously undocumented Windows backdoor used in a cyber-espionage campaign. It derives part of its decryption key from the serial number of the C drive, is installed through scheduled tasks and malicious Windows services after administrative credentials are obtained, loads its main components into memory, connects to command servers, and can receive plugins for command shell access, file management, keyboard and mouse control, network scanning, credential dumping, keylogging, browser password theft, email collection, and remote access.
Previously known malware assessed to be closely related to BINDCLOAK; the report states BINDCLOAK is likely a variant of OctLurk.
A backdoor family assessed to be closely related to BINDCLOAK, with code similarities and overlapping C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.