hacker-news · Crawled Jul 31, 2026
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
4 IoCs 2 Malware
Read original article ↗
AI Summary
A Chinese-speaking threat actor has been targeting government and public sector organizations in Central Asia since January 2025 using two custom backdoors, OctLurk and SilkLurk, along with a proxy tool called LurkProxy. The malware operates primarily in memory, using obfuscated loaders and victim-specific encoding to evade detection. Post-compromise activities include credential dumping, data exfiltration, remote access via Pandora RC, and lateral movement using tools like Impacket and Fscan.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 47 techniques
T1001 Data Obfuscation · Command And Control T1001.002 Steganography · Command And Control T1001.003 Protocol or Service Impersonation · Command And Control T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1018 Remote System Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1027.002 Software Packing · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1041 Exfiltration Over C2 Channel · Exfiltration T1048 Exfiltration Over Alternative Protocol · Exfiltration T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1070.002 Clear Linux or Mac System Logs · Defense Evasion T1070.003 Clear Command History · Defense Evasion T1070.004 File Deletion · Defense Evasion T1070.005 Network Share Connection Removal · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1075 T1075 T1081 T1081 T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1090.001 Internal Proxy · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1057 Process Discovery · Discovery T1105 Ingress Tool Transfer · Command And Control T1124 System Time Discovery · Discovery