By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Chinese-Speaking Hackers Target Central Asian Governments

A Chinese-speaking threat actor is suspected to be behind a recent surge in cyber attacks targeting government organizations primarily located in Central Asia, with operations commencing in January 2025. The affected nations include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, and Kazakhstan, alongside the Syrian Arab Republic. These targeted entities span various critical sectors, encompassing healthcare, research institutions, and government offices. The campaign leverages two distinct malware families, identified as OctLurk and SilkLurk, to facilitate its malicious objectives. OctLurk, a sophisticated information-stealing malware, is designed to exfiltrate sensitive data from compromised systems. It is characterized by its ability to maintain persistence, evade detection, and communicate with command-and-control (C2) servers. SilkLurk, on the other hand, is a more recent addition to the threat actor's arsenal, exhibiting capabilities for remote access and data manipulation. The observed attack vectors suggest a multi-stage approach, potentially involving spear-phishing campaigns or the exploitation of known vulnerabilities to gain initial access. The threat actor's focus on government entities in Central Asia indicates a strategic interest in the region, possibly for espionage, intelligence gathering, or to disrupt governmental operations. The use of Chinese-speaking indicators, such as code comments or infrastructure, points towards a state-sponsored or state-aligned group. This campaign highlights the persistent and evolving nature of cyber threats targeting critical infrastructure and governmental bodies globally. The sophistication of the malware employed, coupled with the targeted nature of the attacks, underscores the need for enhanced cybersecurity measures and threat intelligence sharing among affected nations. Further analysis of the malware's code and infrastructure is ongoing to better understand the full scope of the operation and attribute it to specific entities. The ongoing nature of these attacks necessitates vigilance and proactive defense strategies from the targeted governments to mitigate potential damage and protect sensitive national information. The specific motivations behind these attacks remain under investigation, but the pattern suggests a deliberate effort to undermine or gain insights into the operations of Central Asian governments. The development and deployment of custom malware like OctLurk and SilkLurk indicate a significant investment in cyber warfare capabilities by the suspected actors. The international community is monitoring these developments closely, as such attacks can have far-reaching geopolitical implications. The reliance on information-stealing and remote access trojans is a common tactic for espionage operations, aiming to gather intelligence that can be used for strategic advantage. The targeting of healthcare and research sectors also suggests an interest in sensitive data that could be valuable for economic or scientific intelligence. The attribution to a Chinese-speaking threat actor is based on linguistic artifacts within the malware code and observed operational patterns, which are often indicative of specific nation-state cyber units.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.