DriveSilkRAT is a modular remote-access trojan used as the principal implant in the SilkParasite cyberespionage operation. Implemented in .NET and C++ variants, it polls a shared Google Drive folder for tasking, executes commands through in-memory .NET plugins, and uploads execution results and collected data through the same cloud service. Its plugin set supports host and network discovery, IP-configuration collection, directory and process enumeration, file display, copying, deletion, execution, and process termination. DriveSilkRAT also deployed other malware families within the SilkParasite toolset. SilkParasite targeted government and economic decision-making entities in Central Asia and Georgia, primarily using spear-phishing Office-document lures, password-protected archives, and DLL sideloading chains. The operation is assessed with medium confidence as China-nexus activity, without attribution to a specific named threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DriveSilkRAT is represented by GoogleDriveClient.exe samples, mutexes, an attacker email address, RC4 keys, and plugins for host/network discovery, file operations, command execution, and process termination.
One of the new tools, DriveSilkRAT, uses Google Drive to exchange data with an infected machine, allowing some malicious traffic to be disguised as communication with a legitimate cloud service.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The command-execution plugin runs processes through Windows Management Instrumentation rather than spawning cmd.exe directly.
DriveSilkRAT ... run it through an in-memory .NET plugin system ... NodeEdgeRAT ... spanning command execution ... SpiceRAT ... equipped to download and run executable binaries and arbitrary commands.
Once opened, the document ran a macro that dropped a signed-application sideloading chain to disk.
It supports 12 plugins for process listing, system and network enumeration, file management, and command execution.
One of the new tools, DriveSilkRAT, uses Google Drive to exchange data with an infected machine, allowing some malicious traffic to be disguised as communication with a legitimate cloud service.
One of the new tools, DriveSilkRAT, uses Google Drive to exchange data with an infected machine, allowing malicious traffic to blend in with traffic from a legitimate cloud service.
DriveSilkRAT operators drop command files into a shared Google Drive folder. The infected host polls that folder, downloads its tasking ... and uploads results back to the same folder.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan serving as the primary SilkParasite payload and distributor for the other six RAT families. It uses a shared Google Drive folder for command-and-control.
A remote access trojan used in the SilkParasite cyberespionage campaign. It enables command execution, file operations, and persistent remote access, and uses Google Drive as a communication channel to blend malicious traffic with legitimate cloud activity.
A remote access trojan used in the SilkParasite cyberespionage campaign. It provides remote access to infected systems and uses Google Drive as a communication channel to blend malicious traffic with legitimate cloud service activity.
Remote access trojan that served as the backbone of the SilkParasite campaign, using Google Drive for command exchange, in-memory plugin loading, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.