Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families

Researchers link a spying campaign against Afghanistan, Kyrgyzstan and neighbours to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a dimly lit government office at night in Southeast Asia, empty desk with a glowing monitor showing abstract green code
Share

Key points

  • A Chinese-speaking hacking crew has targeted government bodies across Central Asia since January 2025, according to reporting first surfaced by The Hacker News.
  • Victims sit in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria, across health, research and government sectors.
  • The intruders use two custom tools, tracked as OctLurk and SilkLurk, pointing to an espionage motive rather than theft for money.
  • Attribution rests on language artefacts and tool overlap, which analysts treat as medium confidence at best.
  • Ordinary citizens in these countries could see knock-on effects if health or research records are quietly siphoned.

A hacking group that appears to speak Chinese has spent most of 2025 breaking into government offices across Central Asia, according to researchers tracking the campaign.

The intrusions started in January 2025 and are still running. Targets include ministries and public bodies in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. Hospitals, research institutes and general government offices all show up in the victim list.

The crew has not been formally tied to a named cluster like Mustang Panda (the CrowdStrike naming) or Earth Preta (the Trend Micro label), both long associated with Chinese state-aligned spying in the region. Language clues and tool design point to a Chinese-speaking operator. That is not the same as a confirmed government link, and honest analysts will say so.

Who is being hit, and why them?

The victims are almost all government-adjacent bodies in countries that sit along China's western border or its Belt and Road corridor. That geography matters. Beijing has a long-running interest in what its neighbours are planning, saying and buying, and spying campaigns against exactly these ministries have been reported for years by multiple vendors.

Hitting healthcare and research sites alongside government offices fits an intelligence pattern rather than a criminal one. There is no ransom note. No data auction. The hackers want to sit quietly and read.

What are OctLurk and SilkLurk?

OctLurk and SilkLurk are two custom pieces of malicious software, meaning programs written to break into a computer and give the attacker remote control. They are named after their behaviour: they lurk. Once inside, they let the operators run commands, steal files and pull more tools down from the internet as needed.

Custom tooling like this is a marker of a resourced group. Off-the-shelf criminal malware would do the job for a smash-and-grab. Building your own suggests you plan to stay a while, and you would rather antivirus vendors did not already have a signature for what you are using.

How confident is the attribution?

Medium confidence, at best, based on what has been published so far. Chinese-language strings inside malware and shared coding habits with older campaigns are useful clues. They are not proof of who pressed the keys.

The overlap in techniques, targeting Central Asian governments, using tailored implants, staying quiet, is consistent with several known Chinese clusters. It is also the kind of pattern a different group could copy. Treat single-source attribution with the usual caution.

What should people in the affected countries do?

Ordinary citizens cannot patch a ministry's network. But if you work in one of the targeted sectors, assume your work email and any research files are of interest. Be sceptical of unexpected attachments, even from colleagues, and report anything odd to your IT team rather than clicking to see what it is.

For everyone else, the risk is indirect. If health or civil records are quietly copied, that data can resurface in fraud attempts months later. Watch for unusual official-looking messages referencing details only a government office should know.

Detail What is known
Campaign start January 2025
Countries hit Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria
Sectors Government, healthcare, research
Tools OctLurk, SilkLurk
Suspected origin Chinese-speaking operator, medium confidence
© 2026 Threat Vectr