Chinese-Speaking Hackers Target Central Asian Governments
A suspected Chinese-speaking threat actor has launched cyberattacks against government and critical infrastructure entities across Central Asia since early 2025. These operations leverage custom malware tools like OctLurk and SilkLurk.
TL;DR
- Attacks began in January 2025, targeting governments in Central Asia and Syria.
- Sectors impacted include healthcare, research, and public administration.
- Attackers use advanced malware tools: OctLurk and SilkLurk.
- Targets are primarily located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, and Kazakhstan.
- The campaign highlights ongoing state-aligned cyber threats to regional stability.
Cybersecurity analysts have identified a coordinated campaign of cyber intrusions attributed to a Chinese-speaking threat actor. Since January 2025, the group has focused on breaching government institutions and key infrastructure across Central Asia.
The targets span multiple sensitive sectors including healthcare, academic research, and public governance. Nations affected include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. This activity underscores the persistent nature of state-aligned cyber threats in geopolitically significant regions.
Malware Arsenal and Tactics
- The attackers deploy two primary malware families: OctLurk and SilkLurk.
- OctLurk functions as a backdoor, enabling remote access and data exfiltration.
- SilkLurk serves as an information stealer, focusing on credential harvesting and system reconnaissance.
- Both tools demonstrate advanced evasion techniques to bypass endpoint defenses.
- Initial access vectors likely involve spear-phishing emails tailored to government personnel.
Impacted Regions and Sectors
- Most attacks concentrated in Central Asian countries including Kyrgyzstan, Tajikistan, and Uzbekistan.
- Healthcare organizations targeted, suggesting possible intelligence-gathering on regional health infrastructure.
- Research institutions compromised, potentially aiming to steal academic or technological data.
- Government offices breached across multiple ministries and administrative bodies.
- The Syrian Arab Republic was also identified as a secondary target region.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.