Find notable cyber news and cases, enriched with sources, timelines, and signals.

Chinese-speaking threat actor Central Asia government campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-sector sectors and using OctLurk, SilkLurk, and LurkProxy to maintain access and steal credentials. The activity has been observed since January 2025, indicating a sustained intrusion thread rather than a one-off event.

Timeline

  1. 31.07.2026 21:52 2 articles · 1h ago

    Chinese-speaking threat actor Central Asia government campaign

    Initial Disclosure

    The earliest visible phase is a fresh wave of attacks against government organizations in Central Asia and Syria that began in January 2025. Initial operations already use custom backdoors and network proxying to establish footholds and support follow-on access.

    Show sources