# Central Asian Governments Face Cyber Threat from Suspected Chinese Hackers

*Published August 3, 2026*
*Source: [https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html](https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html)*

## Executive Summary

Government organizations in Central Asia have been targeted by suspected Chinese-speaking hackers using new malware tools OctLurk and SilkLurk since January 2025. These attacks impact multiple sectors and highlight the evolving tactics of threat actors in maintaining control and evading detection.

## Article

A wave of cyber attacks has been targeting government organizations in Central Asia since January 2025, with a suspected Chinese-speaking threat actor behind the operation. Countries affected include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These attacks have impacted various sectors such as healthcare, research, government offices, foreign ministries, logistics, law enforcement, urban planning, and education. According to Kaspersky, the attacks have not been attributed to any known hacking group. Central to this campaign are two new obfuscated backdoors, OctLurk and SilkLurk, along with a utility called LurkProxy. These tools enable the attackers to download and inject additional malicious plugins, launch command shells, perform file system activities, and carry out network scanning and credential theft. Initial access methods remain unknown, but the attack sequence involves OctLurk being loaded into memory via a loader and connecting to a remote command-and-control server. SilkLurk, another tool used, establishes a TCP connection to a C2 server to execute commands and manage configurations. LurkProxy acts as a reverse proxy to manage network traffic. Kaspersky has noted overlaps in infrastructure between these attacks and previous campaigns involving a C++-based implant named SilentRaid. The use of OctLurk and SilkLurk demonstrates ongoing refinement in threat actor tactics, focusing on stealth and control over compromised networks. These backdoors operate primarily in memory, leaving minimal traces on disk, which complicates detection and reverse engineering efforts.
