Since January 2025, a coordinated cyber campaign has been systematically targeting government organisations across Central Asia and the Middle East. The attack vector is notable not for technical novelty but for its disciplined focus on critical national infrastructure—healthcare, research facilities, and administrative systems that often lack the security resources of Western equivalents.
Geography and Attribution
The suspected actors are Chinese-speaking, according to threat intelligence reporting, and their target list spans Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. This geographic footprint suggests either regional geopolitical interests or supply chain reconnaissance—a pattern seen in earlier campaigns where initial access harvesting precedes larger infrastructure operations.
What makes this campaign noteworthy for infrastructure teams is the sector mix. Healthcare networks are particularly vulnerable because they prioritise availability and operational continuity over strict segmentation. Research institutions often run legacy systems with minimal patching regimes. Government offices in less-resourced regions typically lack centralised threat monitoring. Each represents an asymmetric target.
Malware Delivery and Persistence
The campaign employs two distinct malware families—OctLurk and SilkLurk—which suggests either modular payload selection or separate operator teams conducting parallel intrusions. Without technical details, the naming convention alone indicates these are likely to be information-gathering implants focused on establishing persistent access rather than destructive wiper tools.
The operational model aligns with standard APT methodology: initial compromise via phishing or unpatched services, followed by lateral movement and credential harvesting. Central Asian networks often lack the EDR (endpoint detection and response) coverage and robust logging that would detect such movements quickly. Many organisations in the region still operate without a functioning SOC or equivalent threat detection capability.
Implications for Network Operators
Several defensive lessons apply broadly. First, organisations in regions outside traditional Western security attention often become early-stage testing grounds. Attackers refine techniques against less-defended targets before pivoting to more resistant networks. This means threat intelligence from Central Asia should inform hardening strategies everywhere.
Second, the sector targeting (healthcare and research) reveals that non-defence government agencies receive less protective attention during national security planning. Yet these same agencies often hold sensitive data on citizen health records, government personnel, and technical infrastructure designs. A breach here can enable follow-on attacks against more sensitive targets.
Third, the sustained nature of the campaign—active since January—suggests low friction. Either detection and response capabilities are minimal, or the targets lack the capability to disrupt established access. For hosting providers and infrastructure teams supporting government or healthcare clients in these regions, this means baseline security assumptions must be much more conservative.
Hardening Priorities
Organisations exposed to similar threat actors should prioritise network segmentation over perimeter defence. Central Asian government networks often consist of flatly-routed systems sharing broadcast domains; lateral movement becomes trivial. Implementing VLAN isolation and requiring explicit authentication for inter-network traffic imposes friction on attacker movement.
Credential hygiene deserves equal focus. Harvested credentials from healthcare or research networks become keys to broader government systems. Multi-factor authentication, even SMS-based variants, significantly raises costs. Password managers and centralised identity systems reduce reliance on guessable shared accounts.
Finally, logging and retention matter more than detection systems that don't yet exist. If your organisation cannot afford a SOC, ensure that network traffic and authentication logs are retained for at least 90 days and protected from modification by local administrators. Incident response after the fact is inefficient, but impossible without logs.
The Central Asian campaign demonstrates that state-sponsored operations increasingly target infrastructure that Western security vendors consider secondary markets. This creates both risk and opportunity: organisations that implement disciplined baseline security now will remain ahead of the threat curve even as attackers become more sophisticated.
