SilkParasite Threatens Central Asian Orgs With Flurry of RATs
ID: 8fe9e5dd-abc9-5717-92d7-79f3f6e31f51
STIX ID: report--8fe9e5dd-abc9-5717-92d7-79f3f6e31f51
Feed Name: Dark Reading
Bitdefender Labs reports an active China-nexus cyber‑espionage campaign (attributed to the APT tracked as SilkParasite) targeting government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. The attackers use spear-phishing with regionally tailored documents and password-protected archives to deploy seven remote access trojans (five novel families named DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT, plus SpiceRAT and BloodAlchemy). The malware is small, modular, highly evasive (using trusted services like Google Drive and signed applications), and shows signs of AI-assisted development; defenders are advised to rely on existing detection and preventive controls tuned to these operational patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
