🟠 High  |  Source: The Hacker News


A suspected Chinese-speaking threat actor has been conducting targeted cyber attacks against government and public sector organisations across Central Asia and Syria since January 2025, deploying two previously undocumented malware families dubbed OctLurk and SilkLurk. The campaign spans multiple sectors including healthcare, research, and government offices, indicating a broad intelligence-gathering operation. The use of novel malware tools suggests a well-resourced actor seeking persistent, covert access to sensitive state systems.

Security Architect’s Take: Organisations with cloud workloads supporting government, healthcare, or research functions in the affected regions should review egress traffic for anomalous outbound connections and audit identity and access controls for signs of credential harvesting. Ensure endpoint detection coverage extends to cloud-hosted virtual machines and review threat intelligence feeds for OctLurk and SilkLurk indicators of compromise to update SIEM detection rules promptly.

Original advisory: Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk