Skip to content
Chinacredential-theftendpoint-securityCritical Infrastructure

OctLurk and SilkLurk: new Chinese-speaking backdoors targeting Uzbekistan government agencies

2 min read
Share

OctLurk and SilkLurk: new Chinese-speaking backdoors targeting Uzbekistan government agencies

Kaspersky's Global Research and Analysis Team published primary research on August 7, 2026 documenting two newly identified Windows backdoor families: OctLurk and SilkLurk. Both are being actively used in an ongoing cyberespionage campaign targeting government organizations across Central Asia, with Uzbekistan among the confirmed targets.

What these backdoors do

OctLurk and SilkLurk are Windows-targeting implants with a broadly similar capability set. Both implement keystroke logging, password theft, email and file access, screenshot capture, and remote command execution. The malware communicates with command and control infrastructure in ways consistent with coordinated deployment by a single threat actor or closely coordinated group.

Who is being targeted

Kaspersky confirmed targets in Uzbekistan span multiple sectors: government agencies, ministries, law enforcement agencies, the education sector, and healthcare systems. At least five other countries in Central Asia and adjacent regions are also affected. The campaign has been active since at least 2025.

Attribution

The threat actor is assessed as Chinese-speaking based on tooling characteristics, infrastructure patterns, and targeting profile. Formal attribution to a named advanced persistent threat group has not been confirmed. Kaspersky uses OctLurk and SilkLurk as malware family names, not actor designations.

Why this matters now

Uzbekistan reported a 25-fold increase in cyberattacks on state infrastructure in 2026. The Central Bank of Uzbekistan formally classified cyberattacks as a systemic financial risk earlier this year. A national cybersecurity strategy covering 2026-2030 established dedicated cybersecurity units in key ministries. The OctLurk and SilkLurk campaign is precisely the kind of persistent state-directed threat those units exist to address: long-running, covering multiple sectors, and focused on credential and data access rather than disruptive operations.

What to do

Government organizations in Uzbekistan and across Central Asia should review Kaspersky's Securelist post for the published indicators of compromise, including file hashes, command and control domains, and behavioral signatures. Defenders should check endpoint telemetry for evidence of keylogging processes, unusual screenshot activity, and outbound connections to unfamiliar infrastructure in the relevant time window.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization needs guidance on threat detection or Central Asia threat intelligence.

Related articles