Target-Locked Malware Narrows Central Asia Cyber Espionage Risk
Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia and Syria.

A cyber espionage campaign active since January 2025 has been using malware built to unlock only on specific victim machines, Backend News reported, citing Kaspersky research into attacks on government, healthcare, research and other critical-sector organizations in Central Asia and Syria.
The targeting gives defenders a narrower but more difficult problem than a broad malware outbreak.
Kaspersky’s Global Research and Analysis Team found that the malicious code checks for a unique identifier, such as a computer name or hard drive serial number, before decrypting and running.
On an unintended device or inside a security testing environment, the sample can remain encrypted and inactive, making ordinary analysis less likely to expose it.
Kaspersky identified two custom backdoors, OctLurk and SilkLurk, that provided long-term access to compromised systems.
Once inside, the operators did not install a full malware package at once.
They downloaded only the tools needed for each stage, reducing the amount of suspicious activity visible on a network.
Those tools allowed the attackers to record keystrokes, steal passwords saved in web browsers, read email, capture screenshots, search shared network folders for confidential files and collect login credentials from servers used to manage employee accounts.
Stolen data was packaged with common file-compression software before being sent out.
The operators also deployed the well-known PlugX Remote Access Trojan alongside legitimate remote monitoring software.
That mix gave them multiple ways to maintain access if one tool or route was removed by defenders.
Kaspersky identified victims in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan and Uzbekistan.
The affected organizations included government ministries, law enforcement agencies, logistics providers and urban planning facilities.
The company has not attributed the campaign to a named advanced persistent threat group.
Its researchers assessed with medium confidence that the operators are Chinese-speaking, based on the use of PlugX and similarities in attacker infrastructure.
“Most malware is written once and sent to thousands of targets, which is what makes it easy to catch,” said Saurabh Sharma, lead security researcher at Kaspersky GReAT.
“Here the attackers gave up that scale on purpose.
Preparing a separate build for every victim takes real effort, and it tells you they were more concerned with staying hidden inside a small number of organizations than infecting a lot of them.”
Kaspersky said its products detect both OctLurk and SilkLurk.
It urged organizations to strengthen endpoint protection, monitor networks continuously, secure employee login systems, rotate administrator credentials regularly and use threat intelligence to spot targeted attacks before they spread.




















