SilkParasite Targets Central Asian Governments with Five New RATs

Discover how the SilkParasite operation uses AI-assisted malware and seven RATs to infiltrate government networks across five Central Asian nations.

By Central
SilkParasite's modular architecture and five previously unseen remote access tools mark a new chapter in state-sponsored espionage.
Highlights
  • SilkParasite deploys seven remote access tools, five of which have never been publicly documented before.
  • The campaign targets ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan with precision lures.
  • AI-assisted development in SilkParasite's code represents a new paradigm in cyber espionage attribution challenges.

A previously undocumented cyber espionage operation known as SilkParasite has been systematically compromising government networks across Central Asia, deploying an arsenal of seven remote access tools — five of which have never been seen before. Discovered in late 2025 by Bitdefender Labs, the campaign targets ministries and state entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, with one phishing lure also recovered targeting a Georgian government organization. The threat cluster is assessed with medium confidence to be linked to Chinese-speaking hacking groups, leveraging toolsets that trace back to the infamous PlugX and ShadowPad malware families.

SilkParasite: A New China-Nexus Threat Actor Stalking Central Asian Governments

SilkParasite represents a sophisticated, professionally run espionage campaign that distinguishes itself from other China-linked operations by its hybrid development methodology. The attackers appear to have combined expert human programming with AI-assisted workflows, producing code that shows the hallmarks of human-written logic alongside artifacts of AI generation — most notably in a phishing lure that is “indubitably AI-generated,” according to the researchers who uncovered the operation. This blend of human expertise and machine assistance is a departure from purely AI-generated malware, and it may even be a deliberate tactic to complicate attribution efforts.

The campaign’s geographic focus is striking. Central Asia has become a battleground for cyber espionage, with SilkParasite joining two other prominent threat actors — UAC-0063 and FamousSparrow — that have repeatedly struck the region. What makes SilkParasite’s targeting especially notable is the precision of its lures: documents were crafted to impersonate specific ministries in each of the five Central Asian republics, suggesting deep reconnaissance and a clear strategic interest in the region’s political and economic affairs.

What Is SilkParasite? A Deep Dive into the Cyber Espionage Campaign

SilkParasite is a cyber espionage operation that uses a modular, plugin-based architecture to infiltrate and maintain persistent access to government networks. The attackers rely on spear-phishing emails carrying password-protected RAR archives. The password is supplied in the email body, a common technique to evade email gateways. Inside the archive is a malicious Microsoft Office document that, when opened, runs a macro. That macro executes a DLL sideloading sequence to drop the first-stage payload onto the victim’s machine.

One of the operation’s most sophisticated features is its ability to check for the presence of Kaspersky antivirus before executing its macro. The prevalence of Kaspersky in the region makes this a crucial evasion tactic, allowing the attackers to avoid triggering alerts from the widely used security software.

The Seven Implants: Five New RATs and Two Known Tools

SilkParasite deploys seven distinct remote access tool families, written in four different programming languages: .NET, C++, Go, and JavaScript. Five of these RATs have never been publicly documented before. All share a common design philosophy: they are modular, plugin-oriented, and rely on DLL sideloading as the primary delivery mechanism. Here is a breakdown of each implant:

  • DriveSilkRAT (.NET/C++): This implant uses Google Drive as its command-and-control (C2) infrastructure. It polls a specific folder on Google Drive for tasking, executes commands through an in-memory .NET plugin system, and uploads results back to the same folder. It supports 12 plugins for process listing, system and network enumeration, file management, and command execution. Bitdefender observed roughly 65 infected hosts running DriveSilkRAT, most located in Asia.
  • CookiETagRAT (C++): A stealthy implant that hides C2 traffic within HTTP Cookie and ETag response headers, making it extremely difficult to detect using signature-based network monitoring.
  • NomadRAT (C++): Features a main orchestrator and a dedicated transmitter library that handles all C2 communications. Plugins are fetched from the server by numeric identifiers only when needed, keeping the implant’s on-disk footprint minimal.
  • GoginRAT (Go): Architecturally similar to NomadRAT, but written in Go. It uses a separate transmitter for C2 and implements file system and shell capabilities as independent plugins, with results routed through a shared callback.
  • NodeEdgeRAT (JavaScript): Ships its entire functionality — command execution, file management, and file transfer — in a single script, making it lightweight and easy to deploy.

The two previously documented RATs are BLOODALCHEMY, an updated version of Deed RAT (itself a successor to ShadowPad), and an updated version of SpiceRAT, which is attributed to another Chinese-speaking threat actor known as SneakyChef.

How SilkParasite Exploits AI-Assisted Development — and What It Reveals

The most intriguing aspect of SilkParasite is the evidence of AI-assisted coding. Several artifacts in the malware reveal telltale signs: GoginRAT ships with Go test functions and a hard-coded AES key set to “0123456789abcdef” — a placeholder commonly used in tutorial code. NodeEdgeRAT carries a configuration field for an encryption key set to the literal “change_this_key.” Such placeholder values are typical of AI-generated or AI-assisted code where the developer does not bother to replace them.

More telling is the architectural relationship between NomadRAT and GoginRAT. They share a nearly identical high-level design but are implemented in two different languages — C++ and Go. This suggests that a single design specification was translated into multiple languages, a process that AI copilots are well suited to accelerate. The scale and consistency of this multi-language implementation would be difficult for a small team to achieve manually without significant resources, pointing to AI-assisted workflows as a force multiplier.

However, the campaign’s core engineering is clearly human. The DLL sideloading infrastructure, the plugin architecture, the careful regional tailoring of lures, and the operational security measures all reflect professional espionage tooling developed by experienced human operators. The AI is used to streamline development, not to generate the entire attack framework.

The Attack Chain: From Spear-Phishing Email to Persistent Access

SilkParasite’s attack chain is meticulously designed. It begins with a spear-phishing email containing a password-protected RAR archive. The password is supplied in the email body to prevent automatic scanning. Inside the archive is a malicious Office document that leverages a macro to trigger a DLL sideloading vulnerability. The attackers bring their own copy of a legitimately signed executable and place a rogue DLL in the same directory. When the legitimate binary runs, it loads the malicious DLL, giving the attackers code execution.

This technique is particularly effective because it bypasses many application whitelisting and antivirus controls. The legitimate binary is signed and trusted; the malicious DLL is never flagged because it is loaded from an unusual location. Bitdefender emphasized that the reliable detection signal is not the DLL name but the pairing of a legitimately signed application with a library loaded from an anomalous path.

Once the first-stage payload is deployed, the attackers can expand their foothold using the modular RATs. The plugin-oriented architecture allows them to selectively serve payloads that best adapt to each victim’s environment, keeping the detection footprint small and avoiding the need to deploy the entire arsenal at once.

Why Central Asia Is a Prime Target for Cyber Espionage

Central Asia has emerged as a flashpoint for cyber operations, with governments in the region increasingly targeted by state-sponsored groups. The five countries targeted by SilkParasite — Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan — are strategically important for their energy resources, geopolitical positioning, and proximity to both China and Russia. Government networks in these nations hold sensitive diplomatic, economic, and security information that is highly valuable to intelligence agencies.

The use of BLOODALCHEMY and SpiceRAT, both linked to Chinese-speaking groups, reinforces the assessment that SilkParasite has a China nexus. BLOODALCHEMY was first documented by Elastic Security Labs in October 2023, targeting government organizations in Southern and Southeast Asia. It is a C-based backdoor launched via DLL sideloading and supports basic commands for host information gathering, binary overwrite, and self-uninstallation. SpiceRAT, attributed to SneakyChef, is equipped to download and run executable binaries and arbitrary commands. Both tools are part of a broader ecosystem of Chinese cyber espionage tools that have evolved over decades from PlugX and ShadowPad.

Defensive Strategies: How to Detect and Mitigate SilkParasite Operations

Traditional signature-based detection is largely ineffective against SilkParasite. The attackers use low-footprint plugin-based implants that communicate through legitimate cloud services like Google Drive, making volume-based detection nearly impossible. Bitdefender’s advice is clear: organizations need behavioral baselines that flag unusual relationships between processes and network services, rather than relying on signatures for any single artifact.

The most consistent detection surface across the campaign is DLL sideloading. Security teams should monitor for cases where a signed executable loads a library from an unexpected directory, especially when the executable is running from a user-writable location like Downloads or Temp. Pairing this with network traffic analysis that looks for anomalous connections to cloud storage APIs (like Google Drive) can reveal DriveSilkRAT activity.

Additionally, the use of placeholders like “change_this_key” and hard-coded test keys can be leveraged as YARA rules or endpoint detection patterns. However, these artifacts are easy for attackers to remove in future versions, so they should not be relied upon as primary detection mechanisms.

The Broader Implications: AI-Assisted Malware on the Rise

SilkParasite offers a glimpse into the future of cyber espionage. The combination of human expertise and AI assistance represents a new threat paradigm. AI tools can accelerate development, enable multi-language implementations, and help attackers scale their operations without expanding their human teams. The presence of AI artifacts in the code also introduces a new attribution challenge: adversaries may deliberately include AI-generated lures or placeholder keys to mislead investigators, as SilkParasite may have done.

For defenders, this means the threat landscape is evolving faster than ever. Low-footprint, cloud-resident C2 channels and modular, plugin-based implants will become the norm. Security teams must invest in behavioral detection, user and entity behavior analytics (UEBA), and continuous monitoring of process-to-network relationships. The era of signature-based detection is ending for advanced threats; the era of AI-augmented offense and defense is just beginning.

As SilkParasite continues its operations, Central Asian governments will need to bolster their cybersecurity postures, share threat intelligence across borders, and invest in detection capabilities that can adapt to a rapidly changing adversary. The campaign serves as a stark reminder that even professionally developed, human-crafted malware can be enhanced by AI, making it more resilient, more adaptive, and harder to detect than ever before.

Share This Article