Security researchers have discovered that the OctLurk malware framework is linked to a separate campaign targeting Kazakhstan's critical infrastructure. This connection involves command-and-control (C2) servers previously associated with TrustFall, also known as MystRodX and SilentRaid, which are Linux-focused remote-access malware. OctLurk and its companion backdoor, SilkLurk, have targeted government organizations across Central Asia since January 2025.

Victims include entities in Kazakhstan, Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Syria, and other countries spanning sectors such as government, foreign affairs, healthcare, logistics, law enforcement, research, urban planning, and education. Researchers discovered that several OctLurk and LurkProxy C2 addresses were listed alongside those from Kazakhstan’s State Technical Service (STS) in a public report titled paste.txt.

STS identified an attack campaign targeting Kazakhstan's critical infrastructure in March 2025, using TrustFall—a remote-access malware designed for Linux systems. This finding suggests shared infrastructure across different operating systems campaigns aimed at various targets, indicating potential reuse of resources or coordination between operations. After infection, OctLurk gathers host information including the operating system, computer name, username, local hostname, IP address, and system time.