Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families

Researchers link a spying campaign against Afghanistan, Kyrgyzstan and four neighbouring states to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Full-frame photoreal editorial image of a dimly lit government office at night in Southeast Asia, empty desk with a glowing monitor showing abstract green code
Share

Key points

  • A Chinese-speaking hacking crew has targeted government bodies across Central Asia since January 2025, according to reporting first surfaced by The Hacker News.
  • Victims sit in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria, across health, research and government sectors.
  • The intruders use two custom tools, tracked as OctLurk and SilkLurk, pointing to an espionage motive rather than financial theft.
  • Attribution rests on language artefacts and tool overlap, which analysts treat as medium confidence at best.
  • Citizens in the affected countries could face knock-on effects if health or research records are quietly siphoned.

A hacking group that appears to speak Chinese has spent most of 2025 breaking into government offices across Central Asia, according to researchers tracking the campaign.

The intrusions started in January 2025 and are still running. Targets include ministries and public bodies in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. Hospitals and research institutes show up alongside general government offices in the victim list.

The crew hasn't been formally tied to a named cluster like Mustang Panda (the CrowdStrike naming) or Earth Preta (the Trend Micro label), both long associated with Chinese state-aligned spying in the region. Language clues and tool design point to a Chinese-speaking operator. That's not the same as a confirmed government link, and honest analysts will say so. It's a pattern we've been watching widen: our 27 July report on China-linked hackers hitting Middle East governments with Telegram-concealed malware covered a similar profile of custom tooling against government networks, and the geography is now shifting west.

Who is being hit, and why them?

The victims are almost all government-adjacent bodies in countries that sit along China's western border or its Belt and Road corridor. That geography matters. Beijing has a documented interest in what its neighbours are planning and doing, and spying campaigns against exactly these ministries have been reported for years by multiple vendors.

Hitting healthcare and research sites alongside government offices fits an intelligence pattern rather than a criminal one. There's no ransom note. No data auction. The hackers want to sit quietly and read.

What are OctLurk and SilkLurk?

OctLurk and SilkLurk are custom pieces of malicious software, meaning programs written to compromise a machine and give the attacker remote control. Once inside, they let the operators run commands, exfiltrate files and pull additional tools down from the internet as needed.

Custom tooling like this is a marker of a resourced group. Off-the-shelf criminal malware would serve a smash-and-grab. Building your own suggests you plan to stay a while, and you'd rather antivirus vendors didn't already hold a signature for what you're using.

How confident is the attribution?

Medium confidence, at best, based on what's been published so far. Chinese-language strings inside the malware and shared coding habits with older campaigns are useful clues. They aren't proof of who pressed the keys.

The overlap in techniques: targeting Central Asian governments, using tailored implants, staying quiet, is consistent with several known Chinese clusters. It's also the kind of pattern a different group could replicate. Treat single-source attribution with the usual caution.

Should you worry if you work in one of these sectors?

Ordinary citizens can't patch a ministry's network. But if you work in one of the targeted sectors, assume your work email and research files are of interest. Be sceptical of unexpected attachments, even from internal colleagues, and report anything odd to your IT team. Don't open it to check.

For everyone else, the risk is indirect. If health or civil records are quietly copied, that data can resurface in fraud attempts months later. Watch for unusual official-looking messages referencing details only a government office should know.

Detail What is known
Campaign start January 2025
Countries hit Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria
Sectors Government, healthcare, research
Tools OctLurk, SilkLurk
Suspected origin Chinese-speaking operator, medium confidence
© 2026 Threat Vectr