"New Cyber Espionage Campaign in Central Asia Uncovered, Using Tailored Backdoors"

"New Cyber Espionage Campaign in Central Asia Uncovered, Using Tailored Backdoors"

Researchers have identified two new, highly sophisticated backdoors, OctLurk and SilkLurk, designed specifically for cyber-espionage in the region.

Experts from the cybersecurity firm FireEye have discovered a sophisticated cyber-espionage campaign in Central Asia, utilizing two tailored backdoors: OctLurk and SilkLurkeven though, they operate primarily in memory, the malware injects plugins to launch shells, scan networks, dump credentials, and keylog. The backdoors were first identified in April 2021, but their true impact on the region is only now becoming apparent.

Researchers at the National Cyber Security Centre (NCSC) of the UK, in collaboration with FireEye, have been analyzing the malware and its behavior, and have found that OctLurk and SilkLurk are designed specifically for cyber-espionage in the region. The malware is highly sophisticated, with features such as the ability to inject plugins to launch shells, scan networks, dump credentials, and keylog. The backdoors are also capable of communicating with their command and control servers in a highly encrypted manner.

The malware was first detected in April 2021, but its true impact on the nation is only now becoming apparent. The campaign is believed to have been launched by a nation-state actor, and the malware is thought to have been used to compromise the systems of several major organizations in the region.

FireEye has released a report detailing the malware and its behavior, which can be found on their website. The report provides detailed information about the malware, including its command and control servers, its communication methods, and its impact on the region.

Source: Securelist (Kaspersky)