Since January 2025, a coordinated campaign attributed to Chinese-speaking threat actors has systematically compromised government networks across Central Asia and the broader region. The operation, documented by security researchers tracking malware families including OctLurk and SilkLurk, demonstrates persistent targeting of critical infrastructure in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. What makes this campaign noteworthy for infrastructure operators is not merely its scope, but the methodical approach to persistence and lateral movement within target networks.
Targeting Patterns and Network Vulnerability
The affected organisations span healthcare, research, and government administrative sectors—clusters that typically share common characteristics: legacy systems, constrained IT budgets, and minimal network isolation. Healthcare and research facilities are particularly vulnerable because they often prioritise availability and inter-departmental connectivity over segmentation. A government health ministry managing vaccination records or pandemic response infrastructure often runs flat networks where a single compromised workstation can provide a foothold for lateral traversal to sensitive administrative systems.
Central Asian governments, with few exceptions, operate infrastructure that predates modern zero-trust architecture. Many facilities still rely on perimeter defence models, assuming internal network traffic is inherently trustworthy. Once initial access is established—typically via spear-phishing or exploitation of unpatched internet-facing services—the attacker gains leverage to move across the network with minimal resistance.
Technical Signatures and Persistence Mechanisms
The OctLurk and SilkLurk malware families represent a shift toward modular, feature-rich implants designed for long-term persistence rather than smash-and-grab data theft. These tools typically include capabilities for command-line execution, file exfiltration, and lateral movement across network segments. The presence of multiple malware variants suggests a well-resourced operation with the capacity to maintain separate toolchains for different target environments.
What distinguishes state-sponsored campaigns from commodity cybercriminals is the patience and sophistication applied to maintaining access. Rather than extracting data immediately, these actors establish persistence mechanisms—scheduled tasks, registry modifications, or kernel-level hooks—that allow them to return weeks or months later. For organisations managing critical infrastructure, this persistence model means a single compromise may remain undetected through multiple security audits.
Implications for Government and Critical Infrastructure Hosting
For organisations hosting government or healthcare services in the region, the campaign underscores the importance of network segmentation and traffic inspection. A dedicated administrative network, isolated from public-facing services and monitored with strict egress filtering, can significantly raise the cost of post-exploitation movement. Many compromises that lead to widespread network access occur because database servers, file shares, and administrative consoles are accessible directly from compromised workstations.
Similarly, organisations should assume that standard vulnerability management timelines are inadequate. Nation-state actors will invest weeks in reconnaissance before exploitation, identifying obscure CVEs or zero-days that have no public patch. Regular vulnerability scanning and rapid patching cycles—ideally within days, not months—become operational requirements rather than best practices.
The campaign targeting Central Asian governments also highlights the geopolitical dimension of infrastructure security. Regions perceived as lower-priority by international security vendors often receive minimal attention for threat intelligence and defensive research. This asymmetry allows well-funded state actors to operate with reduced risk of detection.
Detection and Response Considerations
Defenders should look for unusual outbound connectivity patterns, particularly DNS queries to newly registered domains or suspicious IP addresses. Central Asian networks should implement baseline traffic profiles and alert on deviations. Host-based indicators—unexpected scheduled tasks, modifications to system binaries, and unusual service execution—often precede large-scale exfiltration.
Organisations without mature security operations centres should prioritise external threat monitoring and log aggregation. A hosted SIEM solution or third-party managed security service provider can provide the continuous monitoring necessary to detect persistent attackers before they cause significant harm. The scale of this campaign suggests that many compromises may remain undiscovered, with attackers maintaining quiet access for intelligence collection rather than disruptive operations.
For those operating critical infrastructure in contested geopolitical zones, the lesson is straightforward: assume compromise and build network architecture accordingly. Segmentation, encryption, and continuous monitoring are not optional luxuries but foundational requirements for systems that face determined, well-resourced adversaries.

