OctLurk & SilkLurk Backdoors Compromise Government Systems in Six Nations
What Happened — Kaspersky’s research links the OctLurk and SilkLurk Windows backdoors to a sustained cyber‑espionage campaign that has stolen passwords, email archives, and files from government networks in six countries since January 2025.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure of logical‑access controls and credential‑management—core SOC 2 CC6.1 requirements.
- Continuous monitoring of privileged‑account activity and evidence of MFA enforcement are exactly the controls auditors expect to see after an intrusion.
- Mapping this breach to your SOC 2 access‑control framework helps demonstrate due‑diligence and a defensible audit trail.
Who Is Affected — Federal and regional government agencies (public sector) across six unnamed countries.
Recommended Actions
- Review and tighten SOC 2 logical‑access policies: enforce MFA, least‑privilege, and regular credential rotation.
- Deploy continuous privileged‑account monitoring and log‑analysis to capture anomalous backdoor activity.
- Conduct targeted security‑awareness training for administrators and users handling privileged credentials.
Source: HackRead
Technical Notes
- OctLurk and SilkLurk are custom Windows DLL backdoors that persist via registry hijacking and scheduled‑task abuse.
- They exfiltrate data over encrypted C2 channels, leveraging stolen credentials to move laterally.
Source: HackRead