Chinese-speaking threat actors launched coordinated cyberattacks against government organizations across Central Asia and Syria beginning in January 2025, according to security researchers. The campaign targets Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria.

The attackers deployed two malware families in the operation. OctLurk serves as an initial access tool, while SilkLurk functions as a secondary payload for deeper system compromise. Victims span government offices, healthcare facilities, and research institutions across the affected regions.

The targeting pattern suggests a state-sponsored or state-aligned operation. Central Asian governments represent geopolitically significant targets, particularly for Chinese intelligence interests given regional tensions and China's Belt and Road economic initiatives. Syria's inclusion indicates broader regional focus beyond the immediate Central Asian sphere.

Attack methodology remains consistent with sophisticated Chinese-linked campaigns. Initial compromise vectors typically involve phishing or exploitation of unpatched systems, followed by reconnaissance and lateral movement using the secondary payload. Organizations in these regions often operate with legacy infrastructure and limited security resources, making them vulnerable to determined threat actors.

Healthcare and research sector targeting carries particular risk. These organizations hold sensitive epidemiological data, pharmaceutical research, and biological information valuable for both espionage and potential biotech intelligence gathering. Government offices represent standard intelligence collection targets, offering diplomatic and military communications access.

Organizations in affected countries should implement immediate mitigations. Patching critical systems takes priority, particularly in internet-facing applications. Network segmentation isolates high-value assets. Email security hardening blocks common initial vectors. Security monitoring for OctLurk and SilkLurk indicators of compromise should begin immediately.

The campaign underscores persistent targeting of Central Asian infrastructure by Chinese-speaking actors. Previous operations linked to similar threat groups targeted telecommunications providers and government networks throughout the region. This January 2025 wave represents continued operational tempo against