HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Tailored Backdoors “OctLurk” & “SilkLurk” Compromise Government Agencies Across Central Asia

Kaspersky identified two new, heavily‑obfuscated backdoors—OctLurk and SilkLurk—used in a cyber‑espionage campaign against Central Asian government bodies, harvesting credentials, keystrokes and emails. The incident highlights gaps in privileged‑access controls and the need for continuous audit‑ready monitoring.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 securelist.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
securelist.com

Tailored Backdoors “OctLurk” & “SilkLurk” Compromise Government Agencies Across Central Asia

What Happened — Kaspersky’s SecureList reports two newly‑identified, heavily‑obfuscated backdoors—OctLurk and SilkLurk—used in a sustained cyber‑espionage campaign against ministries, law‑enforcement, healthcare, research and education entities in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The loaders create a scheduled task with admin credentials, then deploy plugins for command‑shell access, keylogging, browser‑password theft, email harvesting and network scanning.

Why It Matters for Compliance & Audit Readiness

  • The activity directly violates SOC 2 CC6 (Logical Access) and CC7 (System Operations) controls that require documented, least‑privilege access and continuous monitoring of privileged tasks.
  • Evidence of custom loaders and scheduled tasks demonstrates the need for automated control‑execution logs that can be presented as audit evidence.
  • The campaign’s credential‑dumping capability underscores the importance of robust access‑control policies, MFA enforcement, and security‑awareness training—core elements of a SOC 2‑ready environment.

Who Is Affected – Government & public‑sector organizations (healthcare, research, law‑enforcement, logistics, education) in Central Asia.

Recommended Actions

  • Map the creation of scheduled tasks and use of admin credentials to SOC 2 CC6/CC7 controls; ensure all privileged task creation is logged and reviewed.
  • Deploy continuous endpoint detection (EDR) that captures command‑shell, keylogging and credential‑dumping activity for audit‑ready evidence.
  • Verify MFA enforcement on all privileged accounts and conduct targeted security‑awareness sessions on spear‑phishing and credential‑theft techniques.

Source: SecureList – OctLurk & SilkLurk Backdoors

Technical Notes – The loaders use victim‑specific information to decrypt payloads, hide in scheduled tasks named “GoogleUpDate,” and inject plugins (command shell, keylogger, browser password stealer, email harvester). Post‑compromise tools include Impacket’s secretsdump, FSCAN network scanner and Pandora FMS agents. No public CVE is associated; the threat is a custom, zero‑day‑like backdoor. Source: same as above

📰 Original Source
https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →