Researchers reported that a cyber-espionage operation targeting government and public-sector organizations in Central Asia, with additional victims in Syria, deployed two newly identified backdoors, OctLurk and SilkLurk, alongside a proxy implant called LurkProxy and post-compromise tools including Impacket secretsdump, Browser Password Decryptor, Fscan, WinRAR, 7-Zip, a keylogger, Pandora RC agent, and in one case PlugX. The activity, active since January 2025, used victim-specific decryption, in-memory execution, obfuscation, and plugin-based modules to support command execution, file theft, surveillance, credential access, and remote administration, and is assessed with medium confidence to be operated by the same Chinese-speaking threat actor.
The campaign appears connected through infrastructure overlap to MystRodX, a previously undocumented Linux C++ backdoor delivered by an ELF dropper and initially misclassified as Mirai. MystRodX uses layered encryption, configurable TCP/HTTP communications, and a passive raw-socket “wake-up” mode triggered by crafted DNS or ICMP packets, allowing it to avoid open listening ports; it also maintains persistence through a dual-process guardian mechanism. Prior analysis identified multiple active C2 servers and distinct campaigns tied to separate RSA public keys, and the newly reported overlap with TrustFall, MystRodX, and SilentRaid infrastructure suggests a broader multi-platform espionage ecosystem spanning both Windows and Linux operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Kaspersky reported a cyber-espionage campaign active since January 2025 using the newly identified OctLurk and SilkLurk backdoors against government and public-sector organizations primarily in Central Asia, with additional victims in Syria. The activity also used LurkProxy and other post-exploitation tools, and in at least one case deployed PlugX as a second-stage payload.
XLab assessed that the previously undocumented MystRodX backdoor may have been present since at least an activation timestamp of January 7, 2024. The malware was identified as a stealthy C++ backdoor delivered by a Linux ELF dropper and initially mislabeled as Mirai by antivirus tools.
Kaspersky assessed with medium confidence that the same actor operates both OctLurk and SilkLurk and said the activity is likely tied to a Chinese-speaking threat actor. The report also noted infrastructure overlap with TrustFall, MystRodX, and SilentRaid activity observed by Kazakhstan’s State Technical Service.
XLab disclosed MystRodX as a previously undocumented dual-mode backdoor, detailing its layered encryption, TCP/HTTP communications, passive DNS/ICMP wake-up mode, and dual-process persistence. The researchers also reported three active C2 servers responding to probes and linked observed infrastructure to multiple campaigns, including two named campaigns and additional uncaptured activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurelist.com
Open sourceblog.xlab.qianxin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.