SilkParasite Espionage Campaign Targets Central Asian Governments

A newly identified cyber espionage operation, dubbed SilkParasite, has been targeting government entities across Central Asia. This campaign employs seven distinct remote access tools (RATs), five of which—DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT—are previously undocumented. Discovered in late 2025, SilkParasite is assessed with medium confidence to be linked to China.

Unlike typical AI-generated malware, SilkParasite’s toolkit exhibits characteristics of professional espionage software developed by human operators, with AI likely used to streamline development processes. Notably, the phishing lures used in the campaign appear to be AI-generated, suggesting a deliberate attempt to obfuscate attribution efforts.

SilkParasite is the third significant threat actor to target Central Asia in recent years, following UAC-0063 and FamousSparrow. A key indicator of its Chinese origin is the use of BLOODALCHEMY, an updated version of Deed RAT, which itself evolved from ShadowPad and PlugX—malware families commonly associated with Chinese hacking groups.

Attack vectors involve password-protected RAR archives containing malicious Microsoft Office documents, likely delivered via spear-phishing emails. The email body provides the password to open the archive. Upon opening, a macro initiates a DLL sideloading sequence to deploy the first-stage payload. These lures are regionally tailored, with documents crafted to appear relevant to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, and even a Georgian government entity.

Significantly, the macro checks for the presence of Kaspersky antivirus software before execution, indicating efforts to evade detection, given the software’s prevalence in the region. The tools deployed in the attack feature a plugin-oriented architecture, allowing operators to expand capabilities as needed, adapt to victim environments, and minimize detection footprints.

This development underscores the evolving sophistication of state-sponsored cyber espionage campaigns. The integration of AI in malware development, combined with traditional human expertise, presents a formidable challenge for cybersecurity defenses. Organizations, especially government bodies in targeted regions, must enhance their security measures, including employee training on phishing tactics and the implementation of advanced threat detection systems, to mitigate such threats.