The SilkParasite espionage campaign is one of the most sophisticated operations detected in recent years against government actors in Central Asia . The group, first detected in late 2025 and assessed with moderate certainty as a China-nexus threat, uses seven RAT (Remote Access Tool) families, five of which have never been documented before. According to The Hacker News, the campaign was uncovered by Bitdefender Labs and exhibits characteristics of a professional espionage operation with traces of AI-assisted development code .

The five new RATs identified in the SilkParasite are: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT , and NodeEdgeRAT. These tools, along with two previously known implants, span four different programming languages: .NET, C++, Go , and JavaScript. This diversity is not accidental — it reflects a mature, well-organized group that seeks to maintain a low detection footprint while ensuring agility in its operations.
Notably, SilkParasite is the third prominent threat group to hit Central Asia in recent years, following UAC-0063 and FamousSparrow. One of the elements linking the operation to China is the use of the BLOODALCHEMY, which is an updated version of the Deed RAT — a successor to ShadowPad, which in turn evolved from PlugX. Both ShadowPad and PlugXare widely used by Chinese hackers.
See also: GoSerpent Malware: Spying on Southeast Asian Governments
SilkParasite: Technical details and attack methods
SilkParasite attack chains start with password-protected RAR files containing malicious Microsoft Office documents, which are likely delivered via spear-phishing emails . The password to open the file is provided in the body of the email. Once the document is opened, a macro is triggered that starts a DLL sideloading sequence to install the first payload. DLL sideloading is a technique that hides malicious code inside trusted executable files, making detection extremely difficult.
The decoys were tailored to the target region: the retrieved documents were designed to appear to be related to government entities in Uzbekistan , Turkmenistan , Kyrgyzstan , Tajikistan , and Kazakhstan , with several impersonating specific ministries. It is also noteworthy that the macro checks whether Kaspersky antivirus is installed and running on the machine before executing — an indication of detection evasion attempts , given the prevalence of this particular security program in the region.

Each tool developed as part of the attack implements a plugin-oriented architecture, which allows operators to extend its capabilities at will, while maintaining a small detection footprint. DriveSilkRAT, for example, uses Google Drive as a command-and-control (C2), querying a folder for commands and uploading results to the same folder. It supports 12 plugins for process logging, system and network enumeration, file management, and command execution. CookiETagRAT uses HTTP Cookie and ETag response headers as a C2 mechanism — an extremely difficult technique to detect.
SilkParasite and AI: A New Era in Espionage
One of the most interesting features of SilkParasite is the presence of traces of AI-assisted development within otherwise highly professional code. As Bitdefender Labs, this differs fundamentally from AI-generated malware: here, artificial intelligence is likely used to speed up the development process, create variants, or evade detection, while the core code remains the work of human experts. The clearest sign of AI use is found in a phishing lure that is undoubtedly AI-generated — and it is the only point where the adversary appears to have been careless, raising the possibility that it was a deliberate choice to confuse attribution efforts.
See also: Zimbra zero-click exploit: Russian group steals emails and 2FA codes via CVE-2025-66376
The use of AI in the development of spyware tools represents a worrying trend that is expected to intensify in the coming years. Bitdefender point out that this technology can significantly accelerate the development cycle of new implants, facilitate the creation of variants that evade existing detection signatures, and reduce the cost of entry for less sophisticated threat actors. In the case of SilkParasite, AI appears to be used as an optimization tool by already skilled operators, rather than as a substitute for human expertise.
At the same time, Kaspersky had reported a separate campaign in Central Asia, active since January 2025, targeting government, healthcare, and research organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan , and Syria (using the OctLurk and SilkLurk). This campaign also used DLL sideloading and PlugX, underscoring the continuity of Chinese espionage operations in the region.
SilkParasite: Protection Recommendations for Government Agencies
Given the techniques used by SilkParasite, organizations — and especially government agencies — should take immediate protective measures. First, monitoring for DLL sideloading, unusual process chains, and trusted binaries that launch unexpected modules is critical. Second, inspecting cloud storage and web headers for hidden C2 patterns can reveal active infections.

Additionally, it is recommended to use application allowlisting and verification of signed binaries to reduce the risk of DLL sideloading, as well as segmenting government and administrative networks so that a single compromised workstation cannot directly access high-value systems. Maintaining logs from endpoints, proxies, DNS, and cloud services is also essential to support retroactive detection of rare C2 patterns and gradual delivery of payloads. Finally, restricting outbound access from sensitive endpoints prevents implants from freely communicating with Google Drive, proxy infrastructure, or external command channels.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The SilkParasite campaign is a stark reminder that state-sponsored threat actors continue to evolve their tools and tactics at a rapid pace. The integration of AI into the malware development process, the use of legitimate cloud services for C2, and the plugin architecture that allows for dynamic capability expansion make these threats particularly challenging to counter. Government agencies in Central Asia — and beyond — must urgently upgrade their defense capabilities and invest in advanced threat detection systems.
