logo

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

ID: 8fe9e5dd-abc9-5717-92d7-79f3f6e31f51

STIX ID: report--8fe9e5dd-abc9-5717-92d7-79f3f6e31f51

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Elizabeth Montalbano

...
...

Bitdefender Labs reports an active China-nexus cyber‑espionage campaign (attributed to the APT tracked as SilkParasite) targeting government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. The attackers use spear-phishing with regionally tailored documents and password-protected archives to deploy seven remote access trojans (five novel families named DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT, plus SpiceRAT and BloodAlchemy). The malware is small, modular, highly evasive (using trusted services like Google Drive and signed applications), and shows signs of AI-assisted development; defenders are advised to rely on existing detection and preventive controls tuned to these operational patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.