SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A Chinese-linked cyber-espionage group has launched a sophisticated campaign targeting government organizations in Central Asia, using a range of previously unknown and highly evasive remote access Trojans (RATs) to gain long-term access to sensitive systems. The operation, attributed to an advanced persistent threat (APT) group called SilkParasite, has been tracked by researchers at Bitdefender Labs since late 2025 and appears to be linked to China’s broader efforts to expand its economic influence in the region.

The campaign has focused on government entities across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, with attackers using spear-phishing lures tailored to specific ministries and organizations. The tactics are typical of Chinese-nexus groups: highly targeted and well-researched attacks that exploit regional interests and vulnerabilities. Targets typically receive emails containing regionally relevant Office documents, often password-protected RAR archives, which trigger a macro that launches the malware delivery chain.

The RATs used in the campaign have been identified as coming from seven different families, five of which were previously unknown and given names by Bitdefender: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two families observed are SpiceRAT and BloodAlchemy, both of which have been documented before. Notably, the toolset used is small, modular, and professionally engineered, with signs of AI-assisted development. This suggests that China-linked threat activity continues to evolve and improve in sophistication.

The discovery of SilkParasite’s activities offers valuable insights into China’s geopolitical motivations and its expansion into Central Asia, a region previously dominated by Russian influence. As Martin Zugec, technical solutions director at Bitdefender, notes, “cyber espionage follows influence.” The campaign demonstrates how China is using cyber means to expand its economic reach in the region, collecting sensitive information from governments and organizations that would otherwise be difficult for Beijing to access.

From a technical perspective, the malware deployed by SilkParasite is highly evasive and indicates a shift towards more sophisticated and modular attacks. “This malware is small, modular, and built specifically not to look like malware,” Zugec explains. It uses trusted services like Google Drive for command channels, hides inside legitimate applications, and keeps its footprint deliberately small. This means that traditional detection methods may struggle to identify the malware, making it even more challenging for defenders to detect and respond.

The sharing of tooling and tradecraft across operations by China-nexus groups is also a notable aspect of SilkParasite’s activities. Historically, such campaigns have often been associated with shared backdoors, providing a recognizable technical fingerprint that can link seemingly unrelated operations. The SilkParasite campaign suggests that this trend will continue, making it essential for defenders to be aware of the evolving tradecraft of Chinese-nexus groups.

In conclusion, the SilkParasite operation highlights the growing sophistication and coordination of China-linked cyber-espionage campaigns. As the attacks demonstrate a clear link between economic influence and cyber espionage, organizations in Central Asia and beyond must remain vigilant against these highly targeted and evasive threats. To stay ahead, defenders should focus on developing more advanced detection methods that can identify modular and AI-assisted malware, as well as sharing knowledge and best practices to combat the evolving tradecraft of Chinese-nexus groups.


Source: Dark Reading — 2026-08-19