A suspected Chinese-speaking threat actor has been conducting cyberattacks against government and public sector organisations across Central Asia and Syria since January 2025, targeting sectors including healthcare, law enforcement, and foreign affairs ministries. The campaign deploys two newly identified backdoors — OctLurk and SilkLurk — alongside a network proxying tool called LurkProxy, enabling capabilities such as credential theft, keylogging, remote access, and data exfiltration. Both backdoors operate primarily in memory and use victim-specific encoding tied to machine details, making detection and reverse engineering significantly more difficult.