New OctLurk and SilkLurk Backdoors Target Governments in 6 Countries
Kaspersky has identified two previously undocumented Windows backdoors in a cyber-espionage campaign targeting government organizations and public institutions in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and the Syrian Arab Republic since January 2025. The company named the malware OctLurk and SilkLurk.
According to Kaspersky’s report, the affected organizations include healthcare and research bodies, government offices, foreign ministries, logistics providers, law-enforcement agencies, urban planning departments, facilities managers and public educational institutions.
Researchers note that each infection is prepared for a particular computer. OctLurk derives part of its decryption key from the serial number of the C drive, while SilkLurk computes a hash from the computer name. Those values unlock the payload path and malicious code, making each loader specific to its intended victim.
On infected computers, OctLurk is installed through scheduled tasks and malicious Windows services after the attacker obtains administrative credentials. SilkLurk uses legitimate NVIDIA and Realtek programs to side-load malicious...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE