What Happened and Why It Matters

According to a report by The Hacker News, security researchers have uncovered a series of attacks targeting government agencies across Central Asia. The attackers, believed to be Chinese-speaking, used two new backdoors called OctLurk and SilkLurk to infiltrate networks in countries like Afghanistan, Kazakhstan, and Uzbekistan.

What makes this campaign significant is how the malware operates. These backdoors run almost entirely in memory, leaving few traces on the hard drive. They can steal passwords, capture keystrokes, take screenshots, and even control the infected computer remotely. This is a serious step up in stealth and capability compared to older hacking tools.

Why This Campaign Signals a Shift in Cyber Espionage Tactics

Attackers are moving away from noisy, file-based malware. OctLurk and SilkLurk are built to evade traditional antivirus software by hiding inside a computer’s working memory. They also use victim-specific data—like a drive serial number or computer name—to encode their payloads, making them harder for researchers to analyze.

This modular approach means the hackers can swap out plugins for different tasks. They can scan networks, dump login credentials, or tunnel traffic through a proxy, all from the same core backdoor. That flexibility makes these tools dangerous not just for governments, but for any organization with valuable data.

While the current targets are in Central Asia, the techniques used here will eventually spread. Cybercriminal groups and other state actors study these methods and adapt them for their own campaigns. Australian businesses should pay attention because what works against a government ministry today could be used against a mid-sized logistics firm tomorrow.

What This Means for Australian SMBs

Australian small and mid-sized businesses may think they’re too small to be targeted. But attackers don’t always discriminate. Many of the tools in this campaign—like credential dumpers, keyloggers, and remote access agents—are easy to repurpose against any network with weak defenses.

SMBs in sectors like healthcare, logistics, and education are especially at risk because they hold sensitive data but often lack dedicated cybersecurity teams. A memory-only backdoor like SilkLurk could sit unnoticed for months, stealing client information or financial records. The same lateral movement techniques used to hop from one government server to another could let an attacker move from a receptionist’s PC to the accounting server.

What You Can Do Now

  • Enable multi-factor authentication on all critical systems, especially email and remote access tools. This blocks many credential theft attempts even if passwords are stolen.
  • Use endpoint detection and response (EDR) software that monitors for memory-based attacks and unusual process behavior. Traditional antivirus alone won’t catch OctLurk-style threats.
  • Train employees to recognise phishing emails, because the initial infection often starts with a malicious link or attachment. Simulated phishing exercises help build awareness.
  • Restrict administrative privileges. Only give users the access they absolutely need, and use separate admin accounts for IT tasks. This limits what an attacker can do after breaking in.
  • Regularly update and patch all software, including operating systems, browsers, and third-party tools. Attackers exploit known vulnerabilities to deploy their malware loaders.

Small and mid-sized businesses in Australia often have limited resources, but taking these steps can dramatically reduce the risk. MS&VG provides managed cybersecurity services tailored to SMBs, helping you stay protected against evolving threats without needing an in-house security team.