OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

2026-07-31T08:51:46Zbf57345f0f56f11765ac5a7978ca9be20ac3de8a0e4834087d98ce451c918271
BitLocker-extortionC2DNS-AAAAGenieLockerMSSQLMicrosoft GraphOutlook-calendar-C2RDPRMMToy GhoulsViPNetbackdoorbrowser-stealercredential-dumpingcryptocurrency-theftcyber-espionagedata-exfiltrationindustrial-control-systems-security-device-code-phishingkeyloggingmemory-resident-malwarenetwork-scanningransomwareseed-phrase-theftsupply-chain-attackweb-shell

What happened

Kaspersky Securelist reports July 2026 threat activity spanning Central Asian cyber-espionage backdoors, Toy Ghouls’ GenieLocker ransomware targeting Windows/Linux/ESXi, Mirage Kitten tooling in the Middle East and Africa, BitLocker-based extortion, cloud- and DNS-based C2, supply-chain abuse of ViPNet updates, Southeast Asian government targeting, cryptocurrency credential theft, industrial threats, and Microsoft device-code phishing. The collection reflects significant espionage, ransomware, credential theft, data exfiltration, and identity-abuse activity, but does not identify specific CVEs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
bf57345f0f56f11765ac5a7978ca9be20ac3de8a0e4834087d98ce451c918271
Enrichment time
2026-07-31T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.