{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/memory-resident/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["high"],"_cs_tags":["backdoor","cyber-espionage","memory-resident","central-asia","chinese-speaking"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSince January 2025, government and research organizations across Central Asia - including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria - have been targeted by two sophisticated, memory-resident backdoors: OctLurk and SilkLurk. These tools, likely operated by a Chinese-speaking threat actor, utilize custom loaders that generate decryption keys derived from victim-specific hardware information, such as the C: drive serial number, to perform reflective DLL injection.\u003c/p\u003e\n\u003cp\u003eThe attackers deploy these backdoors by creating malicious Windows services or scheduled tasks (e.g., 'GoogleUpDate') that execute obfuscated batch scripts. Once the backdoor is injected, it communicates with C2 infrastructure via port 443 using a complex, multi-stage XOR and zlib-compression scheme. The malware is highly modular, allowing the operators to download and inject memory-only plugins for command shell execution, filesystem management, keystroke and mouse event synthesis, credential dumping, and keylogging. The campaign also involves 'LurkProxy', a utility with similar architecture used to facilitate network operations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes persistence by creating a scheduled task (e.g., 'GoogleUpDate') or a custom service (e.g., 'NgcCIntSvc', 'Cusrxsrv') on the victim machine using compromised admin credentials.\u003c/li\u003e\n\u003cli\u003eThe persistence mechanism executes a local batch script (e.g., '1.bat' or 'auto.bat') which installs a loader DLL (e.g., 'oleasapi.dll' or 'msbasesysdc.dll') into the system.\u003c/li\u003e\n\u003cli\u003eThe service registry is configured to call the 'RegisterService' export of the loader DLL upon service startup.\u003c/li\u003e\n\u003cli\u003eThe loader DLL performs multi-stage decryption of the payload path using a hard-coded key and a key derived from the victim's hardware (e.g., drive serial number).\u003c/li\u003e\n\u003cli\u003eThe loader retrieves and decrypts the backdoor DLL, then injects it into memory using reflective DLL injection techniques.\u003c/li\u003e\n\u003cli\u003eThe backdoor contacts the C2 server (e.g., 'dns.multitoconference.com') over port 443, transmitting victim system information encrypted with hard-coded XOR keys and zlib compression.\u003c/li\u003e\n\u003cli\u003eThe backdoor receives and loads modular plugins directly into memory to perform post-exploitation activities, including credential dumping, keylogging, and file exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis campaign has successfully compromised government agencies, foreign affairs ministries, and law enforcement entities across Central Asia. If the attack succeeds, the threat actor gains persistent, remote access to sensitive systems, allowing for large-scale data exfiltration, credential theft, and sustained cyber-espionage activities within the targeted sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for suspicious Windows service creation and scheduled task execution patterns associated with backdoor deployment.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on your network to block connections to known C2 domains: 'dns.multitoconference.com' and 'dns.ssentialserv.xyz'.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of unauthorized services with suspect names like 'NgcCIntSvc' or 'Cusrxsrv' as documented in the brief.\u003c/li\u003e\n\u003cli\u003eUse Endpoint Detection and Response (EDR) to alert on memory-resident reflective DLL injection attempts targeting system processes.\u003c/li\u003e\n\u003cli\u003eInvestigate high-entropy command-line arguments in batch scripts occurring in non-standard directories like 'C:\\Users\u0026amp;lt;username\u0026gt;\\Videos'.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T13:38:13Z","date_published":"2026-07-30T13:38:13Z","id":"https://feed.craftedsignal.io/briefs/2026-07-octlurk-silklurk/","summary":"OctLurk and SilkLurk are sophisticated, memory-resident backdoors targeting government and research entities in Central Asia since January 2025, utilizing machine-specific key derivation for payload decryption and modular plugin injection.","title":"OctLurk and SilkLurk Memory-Resident Backdoors Targeting Central Asia","url":"https://feed.craftedsignal.io/briefs/2026-07-octlurk-silklurk/"}],"language":"en","title":"CraftedSignal Threat Feed - Memory-Resident","version":"https://jsonfeed.org/version/1.1"}