apt3 articles
New Backdoors OctLurk and SilkLurk Linked to Chinese-Speaking Hackers Hitting Central Asian Governments
A suspected Chinese-speaking threat actor has been conducting cyberattacks against government and public sector organisations across Central Asia and Syria since January 2025, targeting sectors including healthcare, law enforcement, and foreign affairs ministries. The campaign deploys two newly identified backdoors — OctLurk and SilkLurk — alongside a network proxying tool called LurkProxy, enabling capabilities such as credential theft, keylogging, remote access, and data exfiltration. Both backdoors operate primarily in memory and use victim-specific encoding tied to machine details, making detection and reverse engineering significantly more difficult.
GoSerpent Malware Has Been Quietly Raiding Southeast Asian Governments for Months
Cybersecurity researchers at Kaspersky have uncovered a previously undocumented malware called GoSerpent, which has been targeting government and diplomatic entities in Southeast Asia since late 2025 for espionage and long-term intelligence gathering. The malware connects to a command-and-control server to deploy secondary payloads capable of credential dumping, file collection, and data exfiltration, while also supporting SOCKS5 proxying to mask attackers' true IP addresses. The campaign shares similarities with the known threat actor TetrisPhantom, though definitive attribution remains uncertain, and a separate but related espionage operation by DoNot Team was also disclosed, targeting Bangladesh's military using spear-phishing emails.
ToddyCat's Umbrij Malware Quietly Hijacks Gmail via OAuth Abuse
The ToddyCat APT group has developed a new malware called Umbrij that exploits OAuth 2.0 and the Google API to covertly access victims' Gmail accounts. The tool works by launching a Chromium-based browser in headless mode, hijacking an active Gmail session via remote debugging, and using Puppeteer to automate the OAuth authorization process — ultimately obtaining an access token granting full access to Gmail, Drive, Contacts, and other Google services. Organizations are advised to check for unauthorized OAuth app connections, particularly those named "Google Workspace Migration/Sync for Microsoft Outlook," and revoke any suspicious access tokens.