OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
2026-07-31T08:51:46Z•bf57345f0f56f11765ac5a7978ca9be20ac3de8a0e4834087d98ce451c918271
BitLocker-extortionC2DNS-AAAAGenieLockerMSSQLMicrosoft GraphOutlook-calendar-C2RDPRMMToy GhoulsViPNetbackdoorbrowser-stealercredential-dumpingcryptocurrency-theftcyber-espionagedata-exfiltrationindustrial-control-systems-security-device-code-phishingkeyloggingmemory-resident-malwarenetwork-scanningransomwareseed-phrase-theftsupply-chain-attackweb-shell
What happened
Kaspersky Securelist reports July 2026 threat activity spanning Central Asian cyber-espionage backdoors, Toy Ghouls’ GenieLocker ransomware targeting Windows/Linux/ESXi, Mirage Kitten tooling in the Middle East and Africa, BitLocker-based extortion, cloud- and DNS-based C2, supply-chain abuse of ViPNet updates, Southeast Asian government targeting, cryptocurrency credential theft, industrial threats, and Microsoft device-code phishing. The collection reflects significant espionage, ransomware, credential theft, data exfiltration, and identity-abuse activity, but does not identify specific CVEs
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- bf57345f0f56f11765ac5a7978ca9be20ac3de8a0e4834087d98ce451c918271
- Enrichment time
- 2026-07-31T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.