Return to Threats

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

thehackernews.com 2026-08-01 AI supply chain High

What Happened

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,

Why It Matters

According to Kaspersky and related reporting, a suspected Chinese‑speaking threat actor has been running a tailored cyber‑espionage campaign since January 2025 against government and critical‑sector organizations in Central Asia and Syria, using memory‑resident backdoors OctLurk and SilkLurk plus the LurkProxy utility for covert traffic routing.[1][2][3] These implants support credential theft, keylogging, browser password theft, email collection, network scanning, and remote access, and are customized per victim device using parameters like drive serial numbers to evade generic detection.[1][3][4] From a RealGround perspective, this type of long‑term, highly tailored intrusion is directly relevant to the AI supply chain because the same organizations and networks targeted for espionage are likely to host or consume AI models, data pipelines, and MLOps tooling. A compromise at this level can silently tamper with training data, model artifacts, or orchestration code, enabling stealthy model poisoning or data exfiltration over time; organizations should respond by treating AI infrastructure as part of their critical software supply chain, implementing SBOM-based dependency tracki

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html

Talk to AI CISO