SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A sophisticated cyber-espionage operation linked to China’s advanced persistent threat (APT) groups has been targeting government organizations in Central Asia with a series of remote access Trojans (RATs). The campaign, attributed to an APT group called SilkParasite, uses spear-phishing lures tailored to specific ministries and government entities across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan.

Researchers from Bitdefender Labs have been tracking the activity since late 2025, after they detected an infection at a Central Asian government body involved in economic decision-making. The campaign’s modus operandi involves sending regionally tailored Office documents, sometimes inside password-protected RAR archives, which trigger a macro that launches a malware delivery chain to deploy a RAT when opened.

The attackers have been using a collection of mostly previously unidentified RATs from seven different malware families, including five newly documented types: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two RAT families observed in the campaign are the previously documented SpiceRAT and BloodAlchemy. What’s striking about this toolset is its small size, modularity, and professional engineering, with signs of AI-assisted development.

The activity has direct links to previous China-nexus activity tracked as FamousSparrow and indirect links to the broader ShadowPad-linked ecosystem. However, all of it draws on the same foundational techniques. The discovery of SilkParasite’s attacks is notable for several reasons related to geopolitics, technical prowess, and insight into the evolving tradecraft of China-nexus groups.

From a geopolitical perspective, the campaign demonstrates how China is making economic moves into a space left by receding Russian influence across Central Asia. Cyber espionage follows influence, and SilkParasite’s attacks show how China is collecting information from governments and organizations in a region that used to sit firmly in Moscow’s orbit. The activity also provides clues about the current state of Chinese-nexus malware deployment, which is increasingly more evasive.

The malware deployed by SilkParasite is small, modular, and built specifically not to look like malware. It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small. This means that defenders who continue to hunt for large, self-contained implants will miss what SilkParasite is deploying.

The discovery of SilkParasite’s activity suggests that China-nexus groups share tooling and tradecraft across operations, which could be a harbinger of what’s to come in regions these APTs target worldwide. Historically, China-nexus campaigns have often been associated with shared backdoors: a common implant could surface across operations that seem unrelated, giving defenders a recognizable technical fingerprint.

The takeaway for security professionals is clear: as China-nexus groups continue to evolve and adapt their tradecraft, defenders must stay vigilant and update their detection strategies to account for increasingly evasive malware. By adopting a more nuanced understanding of the threat landscape, organizations can better protect themselves against these sophisticated cyber-espionage operations.


Source: Dark Reading — 2026-08-19