Tailored Backdoors “OctLurk” & “SilkLurk” Compromise Government Agencies Across Central Asia
What Happened — Kaspersky’s SecureList reports two newly‑identified, heavily‑obfuscated backdoors—OctLurk and SilkLurk—used in a sustained cyber‑espionage campaign against ministries, law‑enforcement, healthcare, research and education entities in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The loaders create a scheduled task with admin credentials, then deploy plugins for command‑shell access, keylogging, browser‑password theft, email harvesting and network scanning.
Why It Matters for Compliance & Audit Readiness
- The activity directly violates SOC 2 CC6 (Logical Access) and CC7 (System Operations) controls that require documented, least‑privilege access and continuous monitoring of privileged tasks.
- Evidence of custom loaders and scheduled tasks demonstrates the need for automated control‑execution logs that can be presented as audit evidence.
- The campaign’s credential‑dumping capability underscores the importance of robust access‑control policies, MFA enforcement, and security‑awareness training—core elements of a SOC 2‑ready environment.
Who Is Affected – Government & public‑sector organizations (healthcare, research, law‑enforcement, logistics, education) in Central Asia.
Recommended Actions
- Map the creation of scheduled tasks and use of admin credentials to SOC 2 CC6/CC7 controls; ensure all privileged task creation is logged and reviewed.
- Deploy continuous endpoint detection (EDR) that captures command‑shell, keylogging and credential‑dumping activity for audit‑ready evidence.
- Verify MFA enforcement on all privileged accounts and conduct targeted security‑awareness sessions on spear‑phishing and credential‑theft techniques.
Source: SecureList – OctLurk & SilkLurk Backdoors
Technical Notes – The loaders use victim‑specific information to decrypt payloads, hide in scheduled tasks named “GoogleUpDate,” and inject plugins (command shell, keylogger, browser password stealer, email harvester). Post‑compromise tools include Impacket’s secretsdump, FSCAN network scanner and Pandora FMS agents. No public CVE is associated; the threat is a custom, zero‑day‑like backdoor. Source: same as above