Darkreading SilkParasite APT Targets Central Asian Governments with New RATs
Article Content
- •SilkParasite targets Central Asian government organizations with advanced RATs.
- •Five of the seven identified RAT families are previously undocumented, showcasing sophisticated development.
- •The operation highlights China's expanding influence in Central Asia amid reduced Russian presence.
The SilkParasite cyberespionage operation, linked to a China-nexus APT, is actively targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Bitdefender Labs identified seven remote access Trojan (RAT) families, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The attackers employ spear-phishing tactics, using regionally tailored Office documents and password-protected RAR archives to deliver malware. The campaign aims to establish long-term access to selected victims, leveraging AI-assisted development in its toolset. This operation reflects China's strategic moves into a region previously influenced by Russia, following the latter's declining presence since the 2022 invasion of Ukraine. The threat is assessed at medium confidence, with implications for both regional security and global cyber dynamics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track FamousSparrow and BloodAlchemy in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
FamousSparrow Deploys SparroWocky Backdoor in Latin America The China-aligned cyberespionage group FamousSparrow has replaced its previous backdoor, SparrowDoor, with a new malware called SparroWocky, targeting governmental organizations in Latin America since August 2025. ESET Research attributes this campaign to a likely response to increased U.S. interests in the region.…
TeamFiltration Campaign Targets Microsoft 365 Accounts in Chile A TeamFiltration campaign, codenamed UNK_CondorFiltration, has compromised seven Microsoft 365 accounts across 28 tenants, primarily affecting Chilean retail and financial institutions. The attackers targeted over 5,700 accounts using default or unrotated passwords on unmanaged service accounts, which had no…