OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Kaspersky researchers identified two new backdoors, OctLurk and SilkLurk, used in a coordinated cyber-espionage campaign against government organizations in Central Asia since January 2025. OctLurk deploys via scheduled tasks and Windows services using a loader that decrypts its payload using the victim's C: drive serial number, while SilkLurk uses DLL side-loading of legitimate NVIDIA and Realtek binaries and decrypts payloads using the victim's computer name. Both backdoors support in-memory plugin loading for command shells, file management, keyboard/mouse simulation, and credential theft, with the actor also deploying LurkProxy for network traffic proxying, PlugX as a secondary RAT, and various post-exploitation tools including Impacket secretsdump, keyloggers, and browser password stealers.
- domainabout[.]blsouqs[.]comOctLurk C2 domain
- domainapi2[.]annoyingremote[.]comOctLurk C2 domain
- domainconfbase[.]mdpsupport[.]netOctLurk C2 domain
- domainctyuhjerf[.]kozow[.]comSilkLurk C2 domain
- domaindigital[.]leroymerling[.]comOctLurk C2 domain
- domaindns[.]multitoconference[.]comHard-coded OctLurk backdoor C2 domain, contacted over port 443 for command and plugin delivery
- domaindns[.]ssentialserv[.]xyzLurkProxy C2 domain, resolved to 154.196.162.76; attacker checked connectivity before deploying LurkProxy
- domainfm01[.]clouddevicemetrics[.]comOctLurk C2 domain
- domaingycudore[.]kozow[.]comPlugX RAT C2 domain, configured in the PlugX payload deployed via SilkLurk's command shell
- domainrgnojb[.]casacam[.]netSilkLurk C2 domain
- domainssl[.]blsouqs[.]comOctLurk C2 domain
- domaintj[.]tajikistandip[.]comOctLurk C2 domain
- domaintyhbgtyuj[.]gleeze[.]comSilkLurk C2 domain
- domainuyhvfredc[.]accesscam[.]orgSilkLurk C2 domain
- domainwedfcvbn[.]gleeze[.]comSilkLurk C2 domain
- ip154[.]196[.]162[.]76LurkProxy C2 server IP, used for TLS-encrypted proxy communication on port 64980
- ip154[.]196[.]187[.]73SilkLurk C2 IP address
- ip195[.]86[.]120[.]2SilkLurk C2 IP address
- ip212[.]11[.]39[.]138SilkLurk C2 IP address
- ip45[.]138[.]157[.]165OctLurk C2 IP address
- ip45[.]32[.]152[.]50SilkLurk C2 IP address
- ip45[.]61[.]149[.]112SilkLurk C2 IP address
- ip45[.]77[.]136[.]228SilkLurk C2 IP address
- ip64[.]7[.]198[.]130PlugX C2 IP address
- ip95[.]179[.]141[.]26SilkLurk C2 IP address
- ip95[.]179[.]210[.]138SilkLurk C2 IP address
- md5082d49ef9f14e6811d68c7e0e82e5069OctLurk loader DLL (oleasapi.dll), loaded via service NgcCIntSvc; performs double-XOR decryption and reflective injection of backdoor
- md51415a78b75de7db4ba3d1e61d7db4501OctLurk Command Shell plugin
- md518dc8bff47cc282508354771d0c8cf8cWinRAR binary (RecordedTV.exe/recordutil.exe) used for archiving stolen data
- md52a571f6cee42a17d873f4c942649813fCustom keylogger disguised as AnyDesk.exe, dropped to C:\Users\Public\Pictures\; captures keystrokes and clipboard data
- md52f18472866f38c1e1c2c5c14b9a6ab56SilkLurk loader DLL (vulkan-1.dll), dropped to C:\ProgramData\intel\
- md532a5985543433a4f60da2fafd873b927Renamed Impacket secretsdump portable executable (Adobe.exe), used to extract password hashes from domain controllers
- md537dc84e4bcad92fa28f1e7778d088283Browser Password Decryptor tool (64.exe), extracts passwords from Chrome and Firefox
- md53c9a1ba8e0c7475706adc6376e9d7b7cPlugX dropper (kmsonline.exe), executed via SilkLurk command shell; deploys PlugX via DLL side-loading using legitimate RasTls.exe
- md545cf5916fab4272a1313c26e67aa9220Post-compromise fingerprinting batch script (in.bat) in C:\windows\temp\
- md54e6d5c4770d5a822d7fcce6a74f7ad73Post-compromise fingerprinting batch script (in.bat) variant
- md55e26df131ff0a679a0a2699b723b46e3Pandora RC agent installation batch script (1.bat)
- md562944e26b36b1dcace429ae26ba66164Legitimate binary (RasTls.exe) used for PlugX DLL side-loading
- md56ecf84fb18f6747ed08d7598364d853aOctLurk deployment batch script (1.bat) in user Videos directory
- md57c2f64461bb519c6cbf1fc687675514cOctLurk loader DLL (mscastrac.dll), dropped to C:\ProgramData\intel\
- md58269d6ba1b6842f9152c90cf7add9b93SilkLurk loader DLL (vulkan-1.dll), side-loaded by legitimate NVIDIA nvgwls.exe; decrypts payload using victim computer name hash
- md59a1dd1d96481d61934dcc2d568971d067-Zip binary (7z.exe) used for archiving stolen data
- md5a0cc7accc79abb0287aaba825d0351f0OctLurk backdoor DLL, reflectively injected into memory by the loader; communicates with C2 over port 443
- md5a4d550a3ba0cd073fe3839b99d98a7a8OctLurk Interaction Manager plugin
- md5a56cce62930a6bee80d679b4c495a340OctLurk File Manager plugin
- md5b874123a80fc4f40e06872b9cb54ebc6LurkProxy deployment batch script (auto.bat) on user Desktop
- md5be4731c09734da2e8eb6814a9c82f266SilkLurk loader DLL (vulkan-1.dll), dropped via OctLurk command shell in one incident
- md5cf903e4a1629aa0582fd0363b5786676FSCAN internal network scanning tool (fc.exe), dropped to %TEMP%; scans for services and brute-forces credentials
- md5ef59aad625eebda8650aec5820d6ce69PlugX loader DLL (RasTls.dll), side-loaded by legitimate RasTls.exe binary in C:\ProgramData\Symantec\
- md5f4578e869a735cfad691f927bae3e638OctLurk loader DLL (msbasesysdc.dll), loaded via Cusrxsrv service for LurkProxy deployment
Detection / Hunteropenrouter
What Happened
Security researchers discovered two new types of malicious software (called OctLurk and SilkLurk) that have been secretly installed on government computers across Central Asian countries since early 2025. These programs are designed to let attackers remotely control infected computers, steal files, capture passwords, record keystrokes, and monitor everything the user does. The attackers customized the malware for each victim so that the malicious code can only be unlocked using specific information from that particular computer, making it very difficult for security tools to detect. The attackers also installed additional tools to steal passwords from network servers, scan internal networks for more vulnerable computers, and harvest saved passwords from web browsers. Organizations in government, healthcare, education, and law enforcement in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria are affected. This matters because these backdoors give attackers persistent, hidden access to sensitive government systems and data. Organizations should check for the indicators of compromise listed in the report, review their Windows scheduled tasks and services for suspicious entries, and ensure endpoint detection tools are updated to catch these new threats.
Key Takeaways
- Two newly identified backdoors, OctLurk and SilkLurk, have been deployed in a cyber-espionage campaign targeting government organizations in Central Asia since January 2025.
- Both backdoors use victim-specific encryption keys (C: drive serial number for OctLurk, computer name for SilkLurk) to decrypt payloads, making analysis and generic detection significantly harder.
- SilkLurk employs DLL side-loading via legitimate NVIDIA and Realtek binaries to inject its loader, while OctLurk deploys via scheduled tasks and Windows services.
- The threat actor deploys multiple post-compromise tools including Impacket secretsdump, a custom keylogger, browser password stealers, FSCAN for network scanning, and PlugX as a secondary RAT.
- LurkProxy, a specialized proxy implant sharing OctLurk's architecture, provides SOCKS5 and transparent proxy capabilities on port 64980, enabling traffic relay through compromised hosts.
Affected Systems
- Windows systems in government organizations across Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria)
- Active Directory domain controllers targeted for credential harvesting
- Sectors affected: healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, public education
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Attacker uses stolen admin credentials to create scheduled task 'GoogleUpDate' on remote machines, executing batch scripts (1.bat, auto.bat, in.bat) with SYSTEM privileges
- Execution & Persistence: Batch scripts create Windows services (NgcCIntSvc, Cusrxsrv, RmSs) that load malicious loader DLLs via svchost.exe; SilkLurk uses DLL side-loading via legitimate NVIDIA/Realtek binaries
- Defense Evasion: Loader DLLs perform double-XOR decryption using victim-specific keys (drive serial number or computer name hash) and zlib decompression, then reflectively inject backdoor DLLs into memory
- C2 Communication: Backdoors establish TCP connections to hard-coded C2 servers over port 443 (OctLurk) or configurable ports (SilkLurk), using custom binary protocols with zlib compression and XOR encryption
- Discovery & Credential Access: Attacker uses command shell plugin to fingerprint victims, export RDP logon events, run Impacket secretsdump against domain controllers, deploy keylogger and browser password stealers
- Lateral Movement & Exfiltration: Attacker scans internal networks with FSCAN, uses net use to access shared drives, archives stolen data with WinRAR/7-Zip, and deploys PlugX and Pandora RC as redundant access channels
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article does not include any detection rules. Additional IOCs are stated to be available to Kaspersky Threat Intelligence Reporting customers only.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | The backdoors operate primarily in memory via reflective injection, reducing on-disk artifacts. However, the loader DLLs are written to disk and loaded via services, and post-compromise tools (Adobe.exe, AnyDesk.exe keylogger, fc.exe) are dropped as files. Scheduled task creation and service creation are visible to EDR. The victim-specific encryption makes signature-based detection harder, but behavioral detection of reflective DLL injection and suspicious service creation is feasible. |
| Network Visibility | Medium | OctLurk communicates over port 443 to hard-coded C2 domains, which blends with legitimate HTTPS traffic. LurkProxy listens on port 64980 and connects to its C2 via TLS. SilkLurk supports proxy connections. DNS queries to the listed C2 domains are detectable via DNS logging. The custom binary protocols with zlib compression and XOR encryption are not standard TLS, so deep packet inspection could flag anomalies on port 443. |
| Detection Difficulty | Hard | Victim-specific encryption keys prevent generic payload extraction. Reflective DLL injection leaves minimal disk artifacts. DLL side-loading uses legitimate signed binaries. C2 traffic over port 443 blends with normal HTTPS. Service names mimic legitimate Windows services. Multiple staging directories and shared infrastructure across campaigns complicate attribution and detection. |
Required Log Sources
- Windows Security Event Log (Event IDs 4624, 4688, 4698, 7045, 7036)
- Windows System Event Log (service creation/modification)
- Windows Task Scheduler operational log
- DNS query logs
- Network flow data (NetFlow/Zeek) for port 443 and port 64980
- EDR process creation and module loading telemetry
- File creation events in C:\ProgramData, C:\Users\Public, %TEMP%
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for Windows services created with ServiceDll pointing to DLLs in atypical locations such as C:\ProgramData\intel, C:\Users\Public, or C:\ProgramData\Microsoft\Network\Connections\ rather than C:\Windows\System32. | Windows System Event Log Event ID 7045 (service installed), EDR service creation events, registry monitoring for HKLM\SYSTEM\CurrentControlSet\Services*\Parameters\ServiceDll | Persistence | Medium - legitimate software may install services with DLLs in ProgramData, but combined with svchost group modifications this becomes higher fidelity |
| Consider hunting for scheduled tasks named 'GoogleUpDate' (note the capital D) or 'AnyDesk' that execute batch scripts from user directories or temp folders with SYSTEM privileges. | Windows Task Scheduler operational log, Event ID 4698 (scheduled task created), EDR scheduled task creation events | Execution / Persistence | Low - the misspelled 'GoogleUpDate' is specifically designed to mimic 'GoogleUpdate' but is distinct; legitimate Google Update tasks use the correct spelling |
| Consider hunting for legitimate NVIDIA or Realtek binaries (nvgwls.exe, RtkNGUI64.exe, RtkSmbus.exe, NetSetSvc.exe) executing from non-standard directories such as C:\ProgramData\ rather than their typical installation paths. | EDR process execution logs with full path information, Sysmon Event ID 1 (process creation) with image path | Defense Evasion / Execution | Low - these binaries have well-known default installation paths; execution from ProgramData or user directories is highly suspicious |
| Consider hunting for network connections to port 64980 on any internal host, which would indicate LurkProxy SOCKS5 proxy activity. | Network flow data, Zeek connection logs, firewall logs, EDR network connection events | C2 / Lateral Movement | Low - port 64980 is non-standard and unlikely to be used by legitimate services |
| Consider hunting for renamed Impacket secretsdump executables being run from temp directories or user folders targeting domain controllers with -just-dc-user or similar arguments. | EDR process creation with command line arguments, Windows Security Event Log, Sysmon Event ID 1 | Credential Access | Medium - legitimate administrative tools may use similar arguments, but execution from temp/user directories with non-standard filenames is suspicious |
Control Gaps
- Network-based detection may miss C2 traffic over port 443 using custom binary protocols that do not conform to TLS standards
- Victim-specific payload encryption prevents static analysis and signature-based detection of the backdoor payloads
- Reflective DLL injection into memory bypasses file-based AV scanning of the actual backdoor code
- DLL side-loading via legitimate signed binaries may bypass application whitelisting solutions
- Use of stolen admin credentials for remote scheduled task creation may bypass controls if lateral movement monitoring is insufficient
Key Behavioral Indicators
- Service creation with ServiceDll in non-standard paths (C:\ProgramData, C:\Users\Public)
- Scheduled task named 'GoogleUpDate' (capital D) executing batch scripts with SYSTEM privileges
- Legitimate NVIDIA/Realtek binaries executing from C:\ProgramData\ or other non-default directories
- svchost.exe loading DLLs from atypical directories outside C:\Windows\System32\
- Process spawning cmd.exe with /S /C redirecting output to %TEMP%\tmp*.tmp files
- Network connections to port 64980 indicating LurkProxy activity
- Files named OneDrive.dat or Store.dat in C:\ProgramData\ subdirectories acting as encrypted payloads
- Keylogger writing to C:\Users\Public\Libraries\msect\dev0 and dev1 files
False Positive Assessment
Medium - While the specific C2 domains, file hashes, and service names are high-fidelity indicators, some behavioral detections (such as services loading DLLs from ProgramData or batch scripts in temp directories) may generate false positives from legitimate software installations. The misspelled 'GoogleUpDate' scheduled task name is a strong discriminator with low false positive risk. DLL side-loading detections based on legitimate binaries in non-standard paths should be tuned to known good installation directories.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider searching for the listed C2 domains and IPs in DNS logs, proxy logs, and firewall logs to identify potential compromises.
- Consider hunting for Windows services with ServiceDll values pointing to DLLs in C:\ProgramData, C:\Users\Public, or other non-standard directories, particularly services named NgcCIntSvc, Cusrxsrv, RmSs, specitsrc, cmtastsvc, PNRPHostSvc, vmictimerosync, or vmicagent.
- Consider checking for scheduled tasks named 'GoogleUpDate' (note capital D) or 'AnyDesk' that execute batch scripts from user directories or temp folders.
- If your EDR supports host isolation, consider isolating any confirmed compromised hosts while preserving evidence for forensic analysis.
Infrastructure Hardening
- Consider implementing network segmentation to limit lateral movement via SMB and RDP between workstations and domain controllers.
- Evaluate whether blocking outbound connections to the listed C2 IP addresses and domains at perimeter firewalls and DNS resolvers is feasible.
- Consider monitoring for and blocking inbound/outbound traffic on port 64980, which is used by LurkProxy.
- If applicable, consider deploying LAPS or equivalent solutions to reduce the impact of stolen local admin credentials used for remote scheduled task creation.
User Protection
- Consider deploying EDR rules to detect legitimate NVIDIA and Realtek binaries executing from non-standard directories such as C:\ProgramData.
- Evaluate whether your endpoint protection can detect reflective DLL injection behavior in process memory.
- Consider enabling Windows Defender tamper protection and monitoring for registry changes to Defender exclusion settings.
- If supported by your tooling, consider monitoring for credential dumping tools renamed to non-standard filenames executing from temp or user directories.
Security Awareness
- Consider reminding IT staff to verify the spelling of scheduled task names, as attackers use lookalike names such as 'GoogleUpDate' to mimic legitimate 'GoogleUpdate' tasks.
- Consider incorporating awareness of DLL side-loading attacks into existing security training, emphasizing that legitimate signed binaries can be abused to load malicious DLLs.
- If applicable, consider briefing system administrators on the risk of stolen admin credentials being used for remote scheduled task creation via schtasks /Create /S.
MITRE ATT&CK Mapping
Execution
Persistence
Stealth
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Additional IOCs
- Ips:
45[.]138[.]157[.]165- OctLurk C2 IP address95[.]179[.]210[.]138- SilkLurk C2 IP address45[.]77[.]136[.]228- SilkLurk C2 IP address95[.]179[.]141[.]26- SilkLurk C2 IP address45[.]32[.]152[.]50- SilkLurk C2 IP address212[.]11[.]39[.]138- SilkLurk C2 IP address195[.]86[.]120[.]2- SilkLurk C2 IP address154[.]196[.]187[.]73- SilkLurk C2 IP address45[.]61[.]149[.]112- SilkLurk C2 IP address64[.]7[.]198[.]130- PlugX C2 IP address
- Domains:
tj[.]tajikistandip[.]com- OctLurk C2 domainfm01[.]clouddevicemetrics[.]com- OctLurk C2 domainconfbase[.]mdpsupport[.]net- OctLurk C2 domaindigital[.]leroymerling[.]com- OctLurk C2 domainapi2[.]annoyingremote[.]com- OctLurk C2 domainabout[.]blsouqs[.]com- OctLurk C2 domainssl[.]blsouqs[.]com- OctLurk C2 domaintyhbgtyuj[.]gleeze[.]com- SilkLurk C2 domainwedfcvbn[.]gleeze[.]com- SilkLurk C2 domainrgnojb[.]casacam[.]net- SilkLurk C2 domainctyuhjerf[.]kozow[.]com- SilkLurk C2 domainuyhvfredc[.]accesscam[.]org- SilkLurk C2 domain
- File Hashes:
f4578e869a735cfad691f927bae3e638(MD5) - OctLurk loader DLL (msbasesysdc.dll), loaded via Cusrxsrv service for LurkProxy deployment7c2f64461bb519c6cbf1fc687675514c(MD5) - OctLurk loader DLL (mscastrac.dll), dropped to C:\ProgramData\intel\be4731c09734da2e8eb6814a9c82f266(MD5) - SilkLurk loader DLL (vulkan-1.dll), dropped via OctLurk command shell in one incident2f18472866f38c1e1c2c5c14b9a6ab56(MD5) - SilkLurk loader DLL (vulkan-1.dll), dropped to C:\ProgramData\intel\a56cce62930a6bee80d679b4c495a340(MD5) - OctLurk File Manager plugin1415a78b75de7db4ba3d1e61d7db4501(MD5) - OctLurk Command Shell plugina4d550a3ba0cd073fe3839b99d98a7a8(MD5) - OctLurk Interaction Manager plugin2a571f6cee42a17d873f4c942649813f(MD5) - Custom keylogger disguised as AnyDesk.exe, dropped to C:\Users\Public\Pictures; captures keystrokes and clipboard data37dc84e4bcad92fa28f1e7778d088283(MD5) - Browser Password Decryptor tool (64.exe), extracts passwords from Chrome and Firefoxcf903e4a1629aa0582fd0363b5786676(MD5) - FSCAN internal network scanning tool (fc.exe), dropped to %TEMP%; scans for services and brute-forces credentials6ecf84fb18f6747ed08d7598364d853a(MD5) - OctLurk deployment batch script (1.bat) in user Videos directoryb874123a80fc4f40e06872b9cb54ebc6(MD5) - LurkProxy deployment batch script (auto.bat) on user Desktop45cf5916fab4272a1313c26e67aa9220(MD5) - Post-compromise fingerprinting batch script (in.bat) in C:\windows\temp\4e6d5c4770d5a822d7fcce6a74f7ad73(MD5) - Post-compromise fingerprinting batch script (in.bat) variant5e26df131ff0a679a0a2699b723b46e3(MD5) - Pandora RC agent installation batch script (1.bat)18dc8bff47cc282508354771d0c8cf8c(MD5) - WinRAR binary (RecordedTV.exe/recordutil.exe) used for archiving stolen data9a1dd1d96481d61934dcc2d568971d06(MD5) - 7-Zip binary (7z.exe) used for archiving stolen data62944e26b36b1dcace429ae26ba66164(MD5) - Legitimate binary (RasTls.exe) used for PlugX DLL side-loading
- Registry Keys:
HKLM\SYSTEM\CurrentControlSet\Services\NgcCIntSvc\Parameters- Service registry entry for OctLurk loader; ServiceDll set to oleasapi.dll, ServiceMain set to RegisterServiceHKLM\SYSTEM\CurrentControlSet\Services\Cusrxsrv\Parameters- Service registry entry for LurkProxy loader; ServiceDll set to msbasesysdc.dll, ServiceMain set to RegisterServiceHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost- SvcHost registry key modified to register malicious service groups (NgcCIntSvc, Cusrxsrv) for svchost.exe hosting
- File Paths:
C:\Windows\System32\oleasapi.dll- OctLurk loader DLL loaded via NgcCIntSvc serviceC:\Windows\System32\msbasesysdc.dll- LurkProxy/OctLurk loader DLL loaded via Cusrxsrv serviceC:\Users\Public\Pictures\AnyDesk.exe- Custom keylogger disguised as AnyDesk, persisted via scheduled task on logonC:\Users\Public\Libraries\msect\dev0- Keylogger output file storing captured keystrokes (bytes encoded by subtracting 2)C:\Users\Public\Libraries\msect\dev1- Keylogger output file storing clipboard data (bytes encoded by subtracting 2)C:\ProgramData\Symantec\RasTls.exe- Legitimate binary used for PlugX DLL side-loadingC:\ProgramData\Symantec\RasTls.dll- PlugX loader DLL side-loaded by RasTls.exeC:\ProgramData\Symantec\RasTls.dll.res- PlugX payload file loaded by RasTls.dllC:\ProgramData\microsoft\html help\kmsonline.exe- PlugX dropper executed via SilkLurk command shellC:\ProgramData\Microsoft OneDrive\setup- SilkLurk hardcoded payload path where OneDrive.dat is moved for decryptionC:\ProgramData\Microsoft\Network\Connections\nvgwls.exe- Legitimate NVIDIA binary used for SilkLurk DLL side-loadingC:\ProgramData\Microsoft\Network\Connections\vulkan-1.dll- SilkLurk loader DLL side-loaded by nvgwls.exeC:\ProgramData\intel\vulkan-1.dll- SilkLurk loader DLL in shared staging directory used for both OctLurk and SilkLurkC:\ProgramData\intel\mscastrac.dll- OctLurk loader DLL in shared staging directoryC:\ProgramData\intel\msbasesysdc.dll- OctLurk loader DLL in shared staging directory
- Command Lines:
- Purpose: Create remote scheduled task named GoogleUpDate to deploy OctLurk batch script with SYSTEM privileges | Tools:
cmd.exe,schtasks.exe| Stage: Initial Access / Execution - Purpose: Query status of the GoogleUpDate scheduled task on remote machine before triggering execution | Tools:
cmd.exe,schtasks.exe| Stage: Execution |schtasks /query /S <target> /TN GoogleUpDate /V - Purpose: Run the GoogleUpDate scheduled task on remote machine to execute the deployment batch script | Tools:
cmd.exe,schtasks.exe| Stage: Execution |SCHTASKS /run /S <target> /TN GoogleUpDate - Purpose: Export Security event log filtering for RDP logon events (EventID 4624, LogonType 10) for credential harvesting reconnaissance | Tools:
cmd.exe,wevtutil.exe| Stage: Discovery / Credential Access - Purpose: Execute renamed Impacket secretsdump to extract password hashes from domain controller | Tools:
cmd.exe,Adobe.exe (secretsdump)| Stage: Credential Access |<secretsdump_path> <target> -no-pass -just-dc-user <user> - Purpose: Create scheduled task named AnyDesk to persist keylogger on user logon | Tools:
cmd.exe,schtasks.exe| Stage: Persistence - Purpose: Check connectivity to LurkProxy C2 server before deploying the proxy implant | Tools:
cmd.exe,ping.exe| Stage: Pre-deployment Check |ping <c2_domain> -n 1
- Purpose: Create remote scheduled task named GoogleUpDate to deploy OctLurk batch script with SYSTEM privileges | Tools:
- Other:
GoogleUpDate- Scheduled task name used by attackers for deploying OctLurk, LurkProxy, and Pandora RC agent via batch scripts with SYSTEM privilegesAnyDesk- Scheduled task name used to persist keylogger on user logonNgcCIntSvc- Malicious Windows service name created to load OctLurk loader DLL (oleasapi.dll) via svchost.exeCusrxsrv- Malicious Windows service name created to load LurkProxy/OctLurk loader DLL (msbasesysdc.dll) via svchost.exeRmSs- Malicious Windows service name created by SilkLurk loader for persistence via nvgwls.exe and vulkan-1.dllSymantecRAS- PlugX persistence service name with display name 'SymantecRAS' and description 'Symantec RAS Services'64980- Hard-coded listening port for LurkProxy SOCKS5 proxy on all interfaces