Chinese-Speaking Hackers Target Central Asian Governments Using OctLurk, SilkLurk

A suspected Chinese-speaking threat actor has targeted Central Asian government organizations with OctLurk and SilkLurk malware since January 2025, impacting healthcare, research, and government sectors.

Why it matters

This state-sponsored threat actor's operations increase the risk to the cybersecurity of critical government and infrastructure sectors in Central Asia, requiring focused defensive measures.

SOC impact

Defenders should prioritize detection of OctLurk and SilkLurk malware activity and monitor affected sectors such as healthcare and government for signs of compromise or unusual behavior related to this threat actor’s campaigns.

Recommended actions

  1. Identify assets in healthcare, research, and government sectors potentially targeted
  2. Monitor for OctLurk and SilkLurk malware indicators in telemetry
  3. Review network logs for suspicious activity consistent with threat actor tactics
  4. Assess exposure of critical infrastructure systems in Central Asia
  5. Investigate any alerts related to known malware families OctLurk and SilkLurk

Executive Summary

Since January 2025, a suspected Chinese-speaking state-sponsored group has conducted cyber attacks targeting government organizations across Central Asia. Their campaigns focus on critical sectors including healthcare, research, and government, employing sophisticated malware families named OctLurk and SilkLurk. These operations underscore a persistent threat to regional cybersecurity, highlighting the need for vigilant monitoring of affected sectors and malware activity. Security teams should concentrate on detecting these specific malware threats and assessing the exposure of critical government assets to understand and mitigate potential compromises.

SOC Impact

Defenders should prioritize detection of OctLurk and SilkLurk malware activity and monitor affected sectors such as healthcare and government for signs of compromise or unusual behavior related to this threat actor’s campaigns.

Detection and Exposure Assessment

  • Identify assets in healthcare, research, and government sectors potentially targeted
  • Monitor for OctLurk and SilkLurk malware indicators in telemetry
  • Review network logs for suspicious activity consistent with threat actor tactics
  • Assess exposure of critical infrastructure systems in Central Asia
  • Investigate any alerts related to known malware families OctLurk and SilkLurk

Why It Matters

This state-sponsored threat actor’s operations increase the risk to the cybersecurity of critical government and infrastructure sectors in Central Asia, requiring focused defensive measures.

Source