Malware

SilentRaid

Also known as: MystRodX

According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.

Indicators of Compromise 80

Domain 8[.]8[.]8[.]8 Domain about[.]blsouqs[.]com Domain api2[.]annoyingremote[.]com Domain confbase[.]mdpsupport[.]net Domain ctyuhjerf[.]kozow[.]com Domain digital[.]leroymerling[.]com Domain dns[.]multitoconference[.]com Domain dns[.]ssentialserv[.]xyz Domain fm01[.]clouddevicemetrics[.]com Domain gycudore[.]kozow[.]com Domain rgnojb[.]casacam[.]net Domain ssl[.]blsouqs[.]com Domain tj[.]tajikistandip[.]com Domain tyhbgtyuj[.]gleeze[.]com Domain uyhvfredc[.]accesscam[.]org Domain wedfcvbn[.]gleeze[.]com Filename .pkgdb Filename 1.bat Filename 7z.exe Filename Adobe.exe Filename AnyDesk.exe Filename Bulbature Filename DriveSwitch Filename OctLurk Command Shell plugin Filename OctLurk File Manager plugin Filename OctLurk Interaction Manager plugin Filename OctLurk backdoor Filename RasTls.dll Filename RecordedTV.exe Filename RushDrop Filename SilentRaid Filename auto.bat Filename busybox Filename chargen Filename daytime Filename fc.exe Filename in.bat Filename kmsonline.exe Filename msbasesysdc.dll Filename mscastrac.dll Filename oleasapi.dll Filename pp.txt Filename recordutil.exe Filename vulkan-1.dll Filename x64.exe MD5 082d49ef9f14e6811d68c7e0e82e5069 MD5 1415a78b75de7db4ba3d1e61d7db4501 MD5 18dc8bff47cc282508354771d0c8cf8c MD5 2a571f6cee42a17d873f4c942649813f MD5 32a5985543433a4f60da2fafd873b927 MD5 37dc84e4bcad92fa28f1e7778d088283 MD5 3c9a1ba8e0c7475706adc6376e9d7b7c MD5 45cf5916fab4272a1313c26e67aa9220 MD5 4e6d5c4770d5a822d7fcce6a74f7ad73 MD5 5e26df131ff0a679a0a2699b723b46e3 MD5 6ecf84fb18f6747ed08d7598364d853a MD5 7c2f64461bb519c6cbf1fc687675514c MD5 8269d6ba1b6842f9152c90cf7add9b93 MD5 9a1dd1d96481d61934dcc2d568971d06 MD5 a0cc7accc79abb0287aaba825d0351f0 MD5 a4d550a3ba0cd073fe3839b99d98a7a8 MD5 a56cce62930a6bee80d679b4c495a340 MD5 b874123a80fc4f40e06872b9cb54ebc6 MD5 cf903e4a1629aa0582fd0363b5786676 MD5 ef59aad625eebda8650aec5820d6ce69 MD5 f4578e869a735cfad691f927bae3e638 SHA-256 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596 SHA-256 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200 SHA-256 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d IP 154[.]196[.]162[.]76 IP 154[.]196[.]187[.]73 IP 195[.]86[.]120[.]2 IP 212[.]11[.]39[.]138 IP 45[.]138[.]157[.]165 IP 45[.]32[.]152[.]50 IP 45[.]61[.]149[.]112 IP 45[.]77[.]136[.]228 IP 64[.]7[.]198[.]130 IP 95[.]179[.]141[.]26 IP 95[.]179[.]210[.]138

MITRE ATT&CK TTPs 44

T1001
Data Obfuscation
Command And Control
T1001.002
Steganography
Command And Control
T1001.003
Protocol or Service Impersonation
Command And Control
T1003
OS Credential Dumping
Credential Access
T1012
Query Registry
Discovery
T1018
Remote System Discovery
Discovery
T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1027.002
Software Packing
Defense Evasion
T1041
Exfiltration Over C2 Channel
Exfiltration
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1055
Process Injection
Defense Evasion
T1055.001
Dynamic-link Library Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1057
Process Discovery
Discovery
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1070.001
Clear Windows Event Logs
Defense Evasion
T1070.002
Clear Linux or Mac System Logs
Defense Evasion
T1070.003
Clear Command History
Defense Evasion
T1070.004
File Deletion
Defense Evasion
T1070.005
Network Share Connection Removal
Defense Evasion
T1070.006
Timestomp
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1075
T1075
T1081
T1081
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1090
Proxy
Command And Control
T1090.001
Internal Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1114
Email Collection
Collection
T1120
Peripheral Device Discovery
Discovery
T1124
System Time Discovery
Discovery
T1133
External Remote Services
Persistence
T1210
Exploitation of Remote Services
Lateral Movement
T1555
Credentials from Password Stores
Credential Access
T1566
Phishing
Initial Access
T1566.001
Spearphishing Attachment
Initial Access

Source Articles

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor has been targeting government and public sector organizations in Central Asia since January 2025 using two custom backdoors, OctLurk and SilkLurk, along with a proxy tool called LurkProxy. The malware operates primarily in memory, using obfuscated loaders and victim-specific encoding to evade detection. Post-compromise activities include credential dumping, data exfiltration, remote access via Pandora RC, and lateral movement using tools like Impacket and Fscan.
hacker-news ·4w ago
UAT-7290 targets high value telecommunications infrastructure in South Asia
Cisco Talos has identified a sophisticated China-nexus APT group tracked as UAT-7290, active since at least 2022, targeting high-value telecommunications infrastructure in South Asia and recently expanding into Southeastern Europe. The group conducts espionage and establishes Operational Relay Box (ORB) nodes using a suite of custom and open-source malware, including RushDrop, DriveSwitch, SilentRaid, and Bulbature. UAT-7290 leverages one-day exploits, SSH brute-forcing, and publicly available proof-of-concept code to compromise edge devices and gain initial access. Technical overlaps with APT10 and Red Foxtrot, as well as shared infrastructure and malware traits, suggest ties to Chinese state-sponsored actors.
static-urls
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Kaspersky researchers identified a cyber-espionage campaign targeting government and public sector organizations in Central Asia since January 2025, using two custom backdoors: OctLurk and SilkLurk. Both backdoors are heavily obfuscated, deployed via customized loaders that use victim-specific data for decryption, and support plugin-based post-compromise activities including credential theft, keylogging, remote access, and data exfiltration. The same threat actor, assessed as Chinese-speaking, operates both backdoors and has deployed secondary payloads such as PlugX and Impacket's secretsdump. Infrastructure overlap with the TrustFall (MystRodX/SilentRaid) campaign suggests coordinated multi-platform operations.
securelist ·4w ago