Site icon Back End News

Kaspersky finds custom malware targeting governments and research in Central Asia

Kaspersky logo

A cyber espionage campaign that has been operating since January 2025 is using highly customized malware to infiltrate government agencies, healthcare organizations, research institutions, and other critical sectors across Central Asia and Syria, according to cybersecurity company Kaspersky.

Researchers from Kaspersky’s Global Research and Analysis Team (GReAT) said the attackers created malware that only works on a specific target’s computer. Instead of running on any infected machine, the malicious software checks for a unique identifier, such as a computer name or hard drive serial number, before unlocking itself.

This approach makes the malware much harder for security software to detect because it remains encrypted and inactive when analyzed in a secure testing environment.

Kaspersky identified two custom backdoors, named OctLurk and SilkLurk, that give attackers long-term access to compromised systems. Once inside a network, the attackers download only the tools they need instead of installing a full malware package at once, helping them avoid detection.

The additional tools allow operators to record keystrokes, steal passwords saved in web browsers, read email, capture screenshots, search shared network folders for confidential files, and collect login credentials from servers that manage employee accounts. The attackers also package stolen data using common file-compression software before sending it out.

To maintain access even if one method is removed, the operators also deployed the well-known PlugX Remote Access Trojan (RAT) alongside legitimate remote monitoring software.

Victims identified by Kaspersky include organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. The targets include government ministries, law enforcement agencies, logistics providers, and urban planning facilities.

Although Kaspersky has not officially attributed the attacks to a specific advanced persistent threat (APT) group, researchers said the use of PlugX and similarities in the attackers’ infrastructure suggest with medium confidence that the operators are Chinese-speaking.

“Most malware is written once and sent to thousands of targets, which is what makes it easy to catch,” said Saurabh Sharma, lead security researcher at Kaspersky GReAT. “Here the attackers gave up that scale on purpose. Preparing a separate build for every victim takes real effort, and it tells you they were more concerned with staying hidden inside a small number of organizations than infecting a lot of them,” 

The findings highlight a growing trend in cyber espionage where attackers prioritize stealth over scale. Instead of infecting thousands of victims, they spend more time customizing malware for a handful of organizations that hold sensitive information.

Although the campaign did not include identified victims in Southeast Asia, the tactics reflect broader cybersecurity concerns in the region, where rapid digital adoption has expanded the number of systems that attackers can target.

Kaspersky said its security products detect both OctLurk and SilkLurk. The company also urged organizations to strengthen endpoint protection, monitor networks continuously, secure employee login systems, rotate administrator credentials regularly, and use threat intelligence to detect targeted attacks before they spread.

Exit mobile version