Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

  • What: A Chinese-nexus group uses RATs in a spear-phishing campaign
  • Impact: Central Asian organizations are targeted for cyber-espionage
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources THREAT INTELLIGENCE CYBERATTACKS & DATA BREACHES VULNERABILITIES & THREATS ENDPOINT SECURITY NEWS SilkParasite Threatens Central Asian Orgs With Flurry of RATs A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs. Elizabeth Montalbano,Contributing Writer August 19, 2026 5 Min Read SOURCE: ANDYWORKS VIA GETTY IMAGES A Chinese-nexus cyber-espionage operation is actively targeting government organizations across Central Asia with a collection of mostly previously unidentified remote access Trojans (RATs) from seven different malware families to establish and maintain long-term access to selected victims. Researchers from Bitdefender Labs began tracking the activity — which they attribute to an advanced persistent threat (APT) group called SilkParasite — in late 2025 after they detected an infection at a Central Asian government body involved in economic decision-making, according to a report published today. The campaign targets government entities across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, using spear-phishing lures tailored to specific ministries and government organizations. Targets typically receive messages that include regionally tailored Office documents — sometimes inside password-protected RAR archives — which, when opened, trigger a macro that launches a malware delivery chain to deploy a RAT. For some of the archives, attackers include the password in the accompanying email to make the attachments harder for security gateways and automated analysis systems to inspect, according to the report. Related:'Turf War' Between Claude Agents Leads to Self-Replicating Malware Of the seven different types of malware detected, five were previously undocumented and subsequently named by Bitdefender: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two RAT families observed in the campaign are the previously documented SpiceRAT and BloodAlchemy. Overall, "the toolset is small, modular, and professionally engineered, and it carries traces of AI-assisted development," according to Bitdefender. The activity demonstrates key strategic and technical evolutions in both China-linked threat activity and attacker use of AI that have global ramifications. SilkParasite's Geopolitical Motivations The activity has direct links to previous China-nexus activity tracked as FamousSparrow, and indirect links to the broader ShadowPad-linked ecosystem, Martin Zugec, technical solutions director at Bitdefender, tells Dark Reading. However, "all of it draws on the same foundational techniques," he says. The discovery of the activity is most notable for several reasons related to geopolitics, technical prowess, and insight into the evolving tradecraft of China-nexus groups, Zugec explains, with the first aspect framing "everything else." SilkParasite's attacks demonstrate how China is making economic moves into a space left by receding Russian influence across Central Asia, given that "cyber espionage follows influence," he says. Related:'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft "SilkParasite is what that shift looks like in telemetry: A China-nexus actor collecting information from governments and organizations in a region that used to sit firmly in Moscow's orbit," Zugec explains. RATs Reveal Global, Not Local Tradecraft From a technical aspect, the novel malware deployed in the activity provides clues to defenders about the current state of Chinese-nexus malware deployment, which is increasingly more evasive. "This malware is small, modular, and built specifically not to look like malware," Zugec says. "It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small." This means that if defenders continue to hunt for "large, self-contained implants," they will miss what SilkParasite is deploying, he says. The third key finding concerns how China-nexus groups share tooling and tradecraft across operations, suggesting that SilkParasite's activity is likely a harbinger of what's to come in regions these APTs target worldwide. Historically, China-nexus campaigns have often been associated with shared backdoors: A common implant could surface across operations that seem unrelated, giving defenders a recognizable technical fingerprint. Related:AI Sends Global Crime Syndicates Into Fraud Nirvana SilkParasite points to a different model in which operators, instead of sharing backdoors, can develop distinct malware families while reusing the same operational techniques and practices across global campaigns. "The technique documented in this report is portable, and it can appear in your environment next week," Zugec warns. AI-Assisted, Not Generated Researchers also found several clues consistent with AI-assisted development of the novel malware used in the campaign, which has a strategic advantage for operators who seek stealth, Zugec says. This evidence includes leftover Go test functions and a conspicuously sequential placeholder encryption key in the Gogin RAT; a configuration value reading change_this_key in NodeEdgeRAT; and a similar high-level architecture shared between NomadRAT and GoginRAT, despite the malware being implemented in different programming languages, according to the report. Using AI as a tool for developing malware rather than using it for full generation is likely a strategic move giving SilkParasite an advantage in stealth, Zugec tells Dark Reading. That's because fully AI-generated malware is poorly suited to sophisticated espionage, as the code is often derivative, bloated, and noisy, he says. "That cuts against everything an APT is trying to do," Zugec explains. "Their craft is minimizing footprint to reach an objective, so trading stealth for speed and volume is a non-starter. This is why we think AI still has very limited utility in real cyber espionage, and why the 'AI is supercharging attacks' narrative does not fit this group." Defending Against SilkParasite SilkParasite's use of a raft of new RATs doesn't necessarily mean defenders need to come up with a new generation of security products — in fact, the contrary is true, Zugec says. It's actually using existing tools paired with a better understanding of how these operations work — and ensuring existing prevention, detection, and response capabilities are strong enough to act on that understanding — that will keep organizations secure, he advises. "Most organizations already own more capability than they realize, and a new platform bolted onto shaky basics just adds noise," he says. Combining existing technology with investing in strong prevention and protection can also help better position defenders against attackers that try to use sheer malware volume against them. "The realistic effect of AI on this kind of threat is not smarter malware; it is more of the same, what we call the industrialization of mediocrity," Zugec says. "Existing tools handle that well." About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like THREAT INTELLIGENCE Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish by Jai Vijayan MAR 17, 2026 THREAT INTELLIGENCE Iran's Cyber-Kinetic War Doctrine Takes Shape by Alexander Culafi MAR 06, 2026 THREAT INTELLIGENCE React2Shell Exploits Flood the Internet as Attacks Continue by Rob Wright DEC 12, 2025 THREAT INTELLIGENCE Chinese Gov't Fronts Trick the West to Obtain Cyber Tech by Nate Nelson OCT 06, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show. Editor's Choice CYBERSECURITY OPERATIONS From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture byArielle Waldman AUG 6, 2026 4 MIN READ APPLICATION SECURITY Microsoft's Patch Tuesday Deluge Continues With August Updates byJai Vijayan AUG 11, 2026 4 MIN READ CYBERATTACKS & DATA BREACHES Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition byRobert Lemos AUG 12, 2026 4 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersec

Share this article