Kyrgyzstan Law Enforcement: New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers

Kyrgyzstan Law Enforcement: New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers

Sophisticated Cyber Espionage Campaign Targets Central Asian Governments

A cyber espionage campaign active since January 2025 has compromised government networks across Central Asia using two custom-built backdoors, OctLurk and SilkLurk. The malware, attributed to a likely Chinese-speaking threat actor, enables deep system control, including keystroke logging, password theft, remote command execution, and data exfiltration.

Targets and Impact
Victims span Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria, with affected organizations including ministries, law enforcement, healthcare, research institutions, logistics, schools, and urban planning offices. The attackers leveraged stolen administrator credentials, malicious scheduled tasks, and additional tools to maintain persistence and extract sensitive data.

Malware Capabilities

  • OctLurk: Customized for each victim, the malware uses machine-specific data to decrypt its payload, evading automated detection. It loads plugins directly into memory, enabling file manipulation, command execution, screenshots, clipboard monitoring, and network scanning. A proxy component allows attackers to route traffic through compromised devices, accessing internal systems undetected.
  • SilkLurk: Disguised as legitimate Windows programs, it decrypts payloads using the victim’s computer name and injects them into memory. The malware searches shared network drives for confidential documents, compressing them for exfiltration. The campaign also deployed PlugX, a modular remote-access trojan linked to Chinese APT groups.

Tactics and Persistence
Attackers employed keyloggers, browser password recovery tools, and credential-dumping utilities to harvest credentials, particularly from Chrome and Firefox. Scheduled tasks with high-level privileges, named to appear benign, ensured long-term access. The use of PlugX further expanded espionage capabilities, including file theft and remote control.

Indicators of Compromise (IoCs)
Command-and-control domains and IPs include:

  • dns.ssentialserv[.]xyz (LurkProxy)
  • 154.196.162[.]76 (LurkProxy server)
  • dns.multitoconference[.]com (OctLurk)
  • gycudore.kozow[.]com (PlugX)
  • ctyuhjerf.kozow[.]com (SilkLurk)

Additional IoCs cover malicious DLLs, batch scripts, and filenames like oleasapi.dll, Adobe.exe, and GoogleUpDate (a disguised scheduled task).

The campaign highlights the risks of behavior-based threats, where attackers exploit legitimate tools and credentials to evade detection. Organizations are advised to monitor for unusual task creation, service installations, and internal scanning activity.

Source: https://cybersecuritynews.com/new-backdoors-let-hackers-keylog/

Noventiq Kyrgyzstan cybersecurity rating report: https://www.rankiteo.com/company/noventiq-kyrgyzstan

"id": "NOV1785486898",
"linkid": "noventiq-kyrgyzstan",
"type": "Cyber Attack",
"date": "1/2025",
"severity": "100",
"impact": "8",
"explanation": "Attack that could bring to a war"
{'affected_entities': [{'industry': 'Public Sector',
                        'location': 'Afghanistan',
                        'name': 'Government of Afghanistan',
                        'type': 'Government'},
                       {'industry': 'Public Sector',
                        'location': 'Kazakhstan',
                        'name': 'Government of Kazakhstan',
                        'type': 'Government'},
                       {'industry': 'Public Sector',
                        'location': 'Kyrgyzstan',
                        'name': 'Government of Kyrgyzstan',
                        'type': 'Government'},
                       {'industry': 'Public Sector',
                        'location': 'Tajikistan',
                        'name': 'Government of Tajikistan',
                        'type': 'Government'},
                       {'industry': 'Public Sector',
                        'location': 'Uzbekistan',
                        'name': 'Government of Uzbekistan',
                        'type': 'Government'},
                       {'industry': 'Public Sector',
                        'location': 'Syria',
                        'name': 'Government of Syria',
                        'type': 'Government'},
                       {'industry': 'Public Sector',
                        'location': 'Central Asia',
                        'type': 'Ministries'},
                       {'industry': 'Public Sector',
                        'location': 'Central Asia',
                        'type': 'Law Enforcement'},
                       {'industry': 'Healthcare',
                        'location': 'Central Asia',
                        'type': 'Healthcare'},
                       {'industry': 'Education/Research',
                        'location': 'Central Asia',
                        'type': 'Research Institutions'},
                       {'industry': 'Logistics',
                        'location': 'Central Asia',
                        'type': 'Logistics'},
                       {'industry': 'Education',
                        'location': 'Central Asia',
                        'type': 'Schools'},
                       {'industry': 'Public Sector',
                        'location': 'Central Asia',
                        'type': 'Urban Planning Offices'}],
 'attack_vector': ['Stolen administrator credentials',
                   'Malicious scheduled tasks'],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Confidential documents',
                                              'Credentials',
                                              'Personally identifiable '
                                              'information']},
 'date_detected': '2025-01-01',
 'description': 'A cyber espionage campaign active since January 2025 has '
                'compromised government networks across Central Asia using two '
                'custom-built backdoors, OctLurk and SilkLurk. The malware, '
                'attributed to a likely Chinese-speaking threat actor, enables '
                'deep system control, including keystroke logging, password '
                'theft, remote command execution, and data exfiltration.',
 'impact': {'data_compromised': 'Sensitive government data, confidential '
                                'documents',
            'identity_theft_risk': 'High (keystroke logging, password theft)',
            'operational_impact': 'Deep system control, data exfiltration, '
                                  'remote command execution',
            'systems_affected': 'Government networks, ministries, law '
                                'enforcement, healthcare, research '
                                'institutions, logistics, schools, urban '
                                'planning offices'},
 'initial_access_broker': {'backdoors_established': ['OctLurk',
                                                     'SilkLurk',
                                                     'PlugX'],
                           'entry_point': 'Stolen administrator credentials'},
 'lessons_learned': 'The campaign highlights the risks of behavior-based '
                    'threats, where attackers exploit legitimate tools and '
                    'credentials to evade detection.',
 'motivation': 'Espionage',
 'post_incident_analysis': {'root_causes': 'Exploitation of stolen '
                                           'credentials, malicious scheduled '
                                           'tasks, and use of legitimate tools '
                                           'for persistence'},
 'recommendations': 'Organizations are advised to monitor for unusual task '
                    'creation, service installations, and internal scanning '
                    'activity.',
 'references': [{'source': 'Cyber Incident Description'}],
 'response': {'enhanced_monitoring': 'Recommended to monitor for unusual task '
                                     'creation, service installations, and '
                                     'internal scanning activity'},
 'threat_actor': 'Likely Chinese-speaking threat actor',
 'title': 'Sophisticated Cyber Espionage Campaign Targets Central Asian '
          'Governments',
 'type': 'Cyber Espionage'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.