Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Analysis of a Modular Cyber Espionage Framework

9ea2f55c1c91d04820f5082cf113c73c6320b157baa98d69654117cfc8458296

TLP:CLEAR
Active

SHA-256 Hash

Description

Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utilit...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Analysis of a Modular Cyber Espionage Framework
Pattern Type
STIX
Confidence
75%
Valid From
Aug 7, 2026 12:00
Total Sightings
0
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 9ea2f55c1c91d04820f5082cf113c73c6320b157baa98d69654117cfc8458296

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.