A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization.
Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Bitdefender said the previously unreported SilkParasite cyberespionage campaign was first discovered in late 2025. The operation targeted government bodies in Central Asia.
Elastic Security Labs first documented the BLOODALCHEMY backdoor, a malware family later cited as one indicator linking SilkParasite to China-nexus activity.
Bitdefender reported on the SilkParasite operation and identified seven RAT families used in the campaign, including five previously undocumented families: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The report also assessed the operation with medium confidence as having a China nexus and noted signs of AI-assisted development.
Bitdefender said SilkParasite successfully infected one unnamed Central Asian government institution involved in economic decision-making. The report did not disclose what data was on the system, whether data was stolen, or how long access was maintained.
The campaign used tailored spear-phishing lures against government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and at least one Georgian government entity. The lures used password-protected RAR archives with malicious Office documents that triggered DLL sideloading.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
timesca.com
Open sourcetimesca.com
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcebusinessinsights.bitdefender.com
Open sourcebitdefender.com
Open sourcetechzone.bitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.