Skip to content
SilkParasite APT Targets Central Asian Governments with New RATs

SilkParasite APT Targets Central Asian Governments with New RATs

First seen 19 Aug 2026, 17:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 20, 2026 at 17:14 UTC
  • •SilkParasite targets Central Asian government organizations with advanced RATs.
  • •Five of the seven identified RAT families are previously undocumented, showcasing sophisticated development.
  • •The operation highlights China's expanding influence in Central Asia amid reduced Russian presence.

The SilkParasite cyberespionage operation, linked to a China-nexus APT, is actively targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Bitdefender Labs identified seven remote access Trojan (RAT) families, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The attackers employ spear-phishing tactics, using regionally tailored Office documents and password-protected RAR archives to deliver malware. The campaign aims to establish long-term access to selected victims, leveraging AI-assisted development in its toolset. This operation reflects China's strategic moves into a region previously influenced by Russia, following the latter's declining presence since the 2022 invasion of Ukraine. The threat is assessed at medium confidence, with implications for both regional security and global cyber dynamics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2025-12-01
SilkParasite campaign detected
Bitdefender Labs began tracking SilkParasite after an infection was identified in a Central Asian government body.
Darkreading
2026-08-19
Bitdefender publishes findings
Bitdefender released a report detailing the SilkParasite operation and its use of seven RAT families targeting Central Asian governments.
Bitdefender
2026-08-19
Spear-phishing tactics revealed
The campaign utilizes tailored Office documents and password-protected RAR archives to deliver malware to targets.
Darkreading

More articles in this cluster (10)

Following this threat?

Track FamousSparrow and BloodAlchemy in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed