A suspected Chinese-speaking threat actor has run a cyber-espionage campaign against government and public-sector organizations in Central Asia since at least January 2025, using the newly identified OctLurk and SilkLurk malware families to maintain persistent access and steal sensitive data. Kaspersky reported victims in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria, and said the modular, largely memory-resident toolset was paired with LurkProxy to support reconnaissance, credential theft, lateral movement, remote access, keylogging, and staged exfiltration with tools such as WinRAR and 7-Zip. Investigators also observed use of secretsdump.py, Fscan, Pandora RC, PlugX, and browser credential theft, while noting infrastructure overlaps with the earlier SilentRaid campaign without making a firm attribution.
Zscaler ThreatLabz said the same activity expanded into the Middle East in July 2026, targeting government entities and the energy sector with BINDCLOAK, a previously undocumented 64-bit Windows backdoor assessed with high confidence to be a variant of OctLurk. Delivered by the MIXEDKEY loader, BINDCLOAK uses TLS over TCP, zlib compression, and dual rolling-XOR message protection, while supporting token theft and impersonation, reflective plugin loading, process discovery, and EDR evasion through indirect import resolution with RtlQueueWorkItem and LoadLibraryW. Researchers linked the operations through shared command-and-control infrastructure and certificate reuse, including domains such as cert.hypersnet[.]com, about.blsouqs[.]com, and ssl.blsouqs[.]com.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz reported that the actor previously observed targeting Central Asia since early 2025 expanded in July 2026 to target government entities in the Middle East, with a focus on the energy sector. This marked a geographic escalation of the campaign beyond Central Asia.
Kaspersky said the cyber espionage activity using the newly identified OctLurk and SilkLurk malware families has been ongoing since at least January 2025. The campaign affected government and public-sector organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and the Syrian Arab Republic.
Kaspersky disclosed a cyber espionage campaign using the newly identified OctLurk and SilkLurk malware families to maintain persistent access in sensitive networks across Central Asia. Investigators said a Chinese-speaking actor was likely responsible, though they did not definitively attribute the operation to a known threat group.
ThreatLabz assessed with high confidence that the newly identified BINDCLOAK backdoor is a variant of OctLurk based on code similarities and shared command-and-control infrastructure. The report tied the Middle East activity to the same threat actor behind the earlier OctLurk campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcezscaler.com
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.