The real break is not the new backdoors themselves. It is that they stay in memory, decrypt per victim, and add new capability later through plugins, so the usual hunt for files, hashes, and static payloads can miss the foothold and miss how far the intrusion has grown.
Kaspersky says OctLurk and SilkLurk have been used since January 2025 against government and public-sector targets in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The loaders are customized for each victim, heavily obfuscated, and the backdoors can expand into shells, network scanning, credential dumping, keylogging, browser password theft, email collection, and remote access.
That makes the first compromise harder to prove and the later behavior harder to bound. If the operator can change function after entry, a simple beachhead can turn into a much broader espionage foothold without leaving the normal disk artifacts defenders rely on.