Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Analysis of a Modular Cyber Espionage Framework

a6b9e7721c6ee95be026054f5a62159329e80629

TLP:CLEAR
Active

SHA-1 Hash

Description

Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utilit...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Analysis of a Modular Cyber Espionage Framework
Pattern Type
STIX
Confidence
75%
Valid From
Aug 7, 2026 12:00
Total Sightings
0
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of a6b9e7721c6ee95be026054f5a62159329e80629

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.