A newly uncovered cyber espionage operation dubbed SilkParasite has been targeting government bodies in Central Asia, according to a technical report from Bitdefender Labs. The threat cluster, first discovered in late 2025, is assessed to be China-nexus with medium confidence. SilkParasite employs seven remote access tool (RAT) families, five of which are previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
Bitdefender noted that the operation shows traces of AI-assisted development, distinguishing it from typical AI-generated malware. The clearest sign is an AI-generated phishing lure, which may be a deliberate attempt to confuse attribution. The attack chains begin with password-protected RAR archives containing malicious Microsoft Office documents, likely delivered via spear-phishing emails. The documents are tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, with one also targeting a Georgian entity.
The malware uses DLL sideloading as the primary delivery vector, often bringing its own legitimately signed program to load malicious DLLs. The implants span .NET, C++, Go, and JavaScript, and feature plugin-oriented architectures that allow operators to expand capabilities while keeping a low detection footprint. Notably, the macro checks for Kaspersky antivirus software before execution, indicating attempts to bypass detection in a region where Kaspersky is prevalent.
SilkParasite is the third prominent threat actor to strike Central Asia recently, following UAC-0063 and FamousSparrow. The operation shares ties to China through the use of BLOODALCHEMY, an updated version of Deed RAT, which itself is a successor to ShadowPad and PlugX. An updated version of SpiceRAT, attributed to the Chinese-speaking actor SneakyChef, is also used. Bitdefender observed roughly 65 instances infected with DriveSilkRAT, mostly in Asia. The report emphasizes that catching such low-footprint, plugin-based implants requires behavioral baselines rather than signature-based detection.
Attack groups: SilkParasite, UAC-0063, FamousSparrow, SneakyChef, REF5961
Malware: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT, BLOODALCHEMY, SpiceRAT, Deed RAT, ShadowPad, PlugX
Companies: Bitdefender, Kaspersky
Original source: thehackernews.com