Malware
SilentRaid
Also known as: MystRodX
According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.
Indicators of Compromise 80
Domain 8[.]8[.]8[.]8 Domain about[.]blsouqs[.]com Domain api2[.]annoyingremote[.]com Domain confbase[.]mdpsupport[.]net Domain ctyuhjerf[.]kozow[.]com Domain digital[.]leroymerling[.]com Domain dns[.]multitoconference[.]com Domain dns[.]ssentialserv[.]xyz Domain fm01[.]clouddevicemetrics[.]com Domain gycudore[.]kozow[.]com Domain rgnojb[.]casacam[.]net Domain ssl[.]blsouqs[.]com Domain tj[.]tajikistandip[.]com Domain tyhbgtyuj[.]gleeze[.]com Domain uyhvfredc[.]accesscam[.]org Domain wedfcvbn[.]gleeze[.]com Filename .pkgdb Filename 1.bat Filename 7z.exe Filename Adobe.exe Filename AnyDesk.exe Filename Bulbature Filename DriveSwitch Filename OctLurk Command Shell plugin Filename OctLurk File Manager plugin Filename OctLurk Interaction Manager plugin Filename OctLurk backdoor Filename RasTls.dll Filename RecordedTV.exe Filename RushDrop Filename SilentRaid Filename auto.bat Filename busybox Filename chargen Filename daytime Filename fc.exe Filename in.bat Filename kmsonline.exe Filename msbasesysdc.dll Filename mscastrac.dll Filename oleasapi.dll Filename pp.txt Filename recordutil.exe Filename vulkan-1.dll Filename x64.exe MD5 082d49ef9f14e6811d68c7e0e82e5069 MD5 1415a78b75de7db4ba3d1e61d7db4501 MD5 18dc8bff47cc282508354771d0c8cf8c MD5 2a571f6cee42a17d873f4c942649813f MD5 32a5985543433a4f60da2fafd873b927 MD5 37dc84e4bcad92fa28f1e7778d088283 MD5 3c9a1ba8e0c7475706adc6376e9d7b7c MD5 45cf5916fab4272a1313c26e67aa9220 MD5 4e6d5c4770d5a822d7fcce6a74f7ad73 MD5 5e26df131ff0a679a0a2699b723b46e3 MD5 6ecf84fb18f6747ed08d7598364d853a MD5 7c2f64461bb519c6cbf1fc687675514c MD5 8269d6ba1b6842f9152c90cf7add9b93 MD5 9a1dd1d96481d61934dcc2d568971d06 MD5 a0cc7accc79abb0287aaba825d0351f0 MD5 a4d550a3ba0cd073fe3839b99d98a7a8 MD5 a56cce62930a6bee80d679b4c495a340 MD5 b874123a80fc4f40e06872b9cb54ebc6 MD5 cf903e4a1629aa0582fd0363b5786676 MD5 ef59aad625eebda8650aec5820d6ce69 MD5 f4578e869a735cfad691f927bae3e638 SHA-256 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596 SHA-256 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200 SHA-256 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d IP 154[.]196[.]162[.]76 IP 154[.]196[.]187[.]73 IP 195[.]86[.]120[.]2 IP 212[.]11[.]39[.]138 IP 45[.]138[.]157[.]165 IP 45[.]32[.]152[.]50 IP 45[.]61[.]149[.]112 IP 45[.]77[.]136[.]228 IP 64[.]7[.]198[.]130 IP 95[.]179[.]141[.]26 IP 95[.]179[.]210[.]138
MITRE ATT&CK TTPs 44
T1001 T1001.002 T1001.003 T1003 T1012 T1018 T1021 T1021.001 T1021.002 T1027 T1027.002 T1041 T1048 T1055 T1055.001 T1056.001 T1057 T1059 T1059.001 T1059.003 T1070.001 T1070.002 T1070.003 T1070.004 T1070.005 T1070.006 T1071 T1071.001 T1075 T1081 T1082 T1083 T1090 T1090.001 T1105 T1110 T1114 T1120 T1124 T1133 T1210 T1555 T1566 T1566.001
Data Obfuscation
Command And Control
Steganography
Command And Control
Protocol or Service Impersonation
Command And Control
OS Credential Dumping
Credential Access
Query Registry
Discovery
Remote System Discovery
Discovery
Remote Services
Lateral Movement
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Software Packing
Defense Evasion
Exfiltration Over C2 Channel
Exfiltration
Exfiltration Over Alternative Protocol
Exfiltration
Process Injection
Defense Evasion
Dynamic-link Library Injection
Defense Evasion
Keylogging
Collection
Process Discovery
Discovery
Command and Scripting Interpreter
Execution
PowerShell
Execution
Windows Command Shell
Execution
Clear Windows Event Logs
Defense Evasion
Clear Linux or Mac System Logs
Defense Evasion
Clear Command History
Defense Evasion
File Deletion
Defense Evasion
Network Share Connection Removal
Defense Evasion
Timestomp
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
T1075
T1081
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Internal Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Peripheral Device Discovery
Discovery
System Time Discovery
Discovery
External Remote Services
Persistence
Exploitation of Remote Services
Lateral Movement
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Spearphishing Attachment
Initial Access
Source Articles
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor has been targeting government and public sector organizations in Central Asia since January 2025 using two custom backdoors, OctLurk and SilkLurk, along with a proxy tool called LurkProxy. The malware operates primarily in memory, using obfuscated loaders and victim-specific encoding to evade detection. Post-compromise activities include credential dumping, data exfiltration, remote access via Pandora RC, and lateral movement using tools like Impacket and Fscan.
hacker-news ·4w ago
UAT-7290 targets high value telecommunications infrastructure in South Asia
Cisco Talos has identified a sophisticated China-nexus APT group tracked as UAT-7290, active since at least 2022, targeting high-value telecommunications infrastructure in South Asia and recently expanding into Southeastern Europe. The group conducts espionage and establishes Operational Relay Box (ORB) nodes using a suite of custom and open-source malware, including RushDrop, DriveSwitch, SilentRaid, and Bulbature. UAT-7290 leverages one-day exploits, SSH brute-forcing, and publicly available proof-of-concept code to compromise edge devices and gain initial access. Technical overlaps with APT10 and Red Foxtrot, as well as shared infrastructure and malware traits, suggest ties to Chinese state-sponsored actors.
static-urls
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Kaspersky researchers identified a cyber-espionage campaign targeting government and public sector organizations in Central Asia since January 2025, using two custom backdoors: OctLurk and SilkLurk. Both backdoors are heavily obfuscated, deployed via customized loaders that use victim-specific data for decryption, and support plugin-based post-compromise activities including credential theft, keylogging, remote access, and data exfiltration. The same threat actor, assessed as Chinese-speaking, operates both backdoors and has deployed secondary payloads such as PlugX and Impacket's secretsdump. Infrastructure overlap with the TrustFall (MystRodX/SilentRaid) campaign suggests coordinated multi-platform operations.
securelist ·4w ago