Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Cybersecurity experts have uncovered evidence of a sophisticated hacking campaign targeting governments and institutions across Central Asia, with suspected Chinese-speaking hackers using custom-built malware tools to breach networks and steal sensitive information.

The attackers are believed to be exploiting a range of vulnerabilities in software applications used by their targets, including Microsoft Exchange servers, Adobe Acrobat, and Oracle Java. The hacking group’s use of advanced AI-powered discovery techniques has allowed them to identify previously unknown weaknesses in these programs, which they then exploit using custom-built malware tools known as OctLurk and SilkLurk.

The malware toolkit is designed to evade detection by traditional antivirus software and firewalls, making it a particularly potent threat. Once inside the network, the hackers can move laterally with ease, accessing sensitive data and potentially even installing additional backdoors for future use. The attackers’ ability to adapt their tactics in real-time, using AI-powered tools to identify new vulnerabilities and adjust their approach accordingly, has made them highly effective.

The hacking campaign appears to be focused primarily on governments and institutions in the Central Asian region, including Kazakhstan, Kyrgyzstan, and Tajikistan. However, cybersecurity experts warn that the malware toolkit is likely designed to be adaptable for use against targets worldwide, making it a significant concern for organizations globally. The fact that the attackers are suspected of being Chinese-speaking hackers has raised concerns about the potential involvement of state-sponsored actors in the operation.

The use of AI-powered discovery techniques by the hacking group highlights the growing threat posed by advanced persistent threats (APTs). These sophisticated attacks require significant resources and expertise, but can have devastating consequences for organizations that fall victim. In this case, the attackers’ ability to identify new vulnerabilities and adapt their approach has allowed them to evade detection and achieve their objectives.

The campaign serves as a stark reminder of the importance of robust cybersecurity practices in today’s digital landscape. Organizations must stay vigilant and proactive in identifying and addressing potential security risks. This includes keeping software applications up-to-date, implementing robust patch management policies, and conducting regular vulnerability assessments. By taking these steps, organizations can reduce their exposure to attacks like this one and protect themselves against the evolving threat landscape.

In light of this campaign, it’s essential for organizations worldwide to prioritize cybersecurity and take a proactive approach to identifying and addressing potential security risks. This includes staying informed about emerging threats and vulnerabilities, implementing robust security controls, and conducting regular security audits to ensure that defenses are adequate. By taking these steps, organizations can reduce their exposure to attacks like this one and protect themselves against the evolving threat landscape.


Source: The Hacker News — 2026-07-31