Chinese-Nexus 'SilkParasite' Campaign Targets Central Asian Governments
A sophisticated espionage operation is deploying a modular toolset of seven RATs to infiltrate economic decision-making entities across Central Asia.
A Chinese-nexus cyber-espionage group dubbed "SilkParasite" is targeting government organizations across Central Asia to establish long-term access to entities involved in economic decision-making. The campaign focuses its efforts on Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan.
To gain entry, the actors employ spear-phishing lures featuring tailored Office documents and password-protected RAR archives. Once inside, the group deploys a modular toolset consisting of seven Remote Access Trojan (RAT) families. According to research from Bitdefender, five of these are previously undocumented—DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT—while two are known threats, SpiceRAT and BloodAlchemy.
Stealth and AI-Assisted Development
The malware is engineered for high stealth, utilizing command channels over trusted services such as Google Drive to blend in with legitimate traffic. Additionally, the tools are designed to hide within legitimately signed applications to evade detection by security software.
Bitdefender researchers identified evidence that the group is using AI to assist in the development of its tools. In the case of GoginRAT, analysts found leftover Go test functions and sequential placeholder encryption keys, which are hallmarks of AI-assisted coding. Martin Zugec, Technical Solutions Director at Bitdefender, described this trend as the "industrialization of mediocrity," noting that the realistic effect of AI is not necessarily smarter malware, but the ability to produce more of the same at a higher volume.
A Shift in Tradecraft
SilkParasite's operations reflect a broader pattern of Chinese-nexus activity expanding into the South Caucasus and Central Asia. The group is linked to the FamousSparrow APT and the wider ShadowPad-linked ecosystem. However, SilkParasite demonstrates an evolution in tradecraft; while previous campaigns often shared common backdoors across different operations, this group develops distinct malware families while reusing the same operational techniques. This approach creates a more portable and evasive model that is harder for defenders to track across different targets.
Geopolitical Implications
This campaign signals a strategic pivot in cyber espionage that mirrors China's growing economic and political influence in regions traditionally dominated by Russia. By targeting the administrative and economic hubs of Central Asia, the actors are collecting intelligence from governments in a region that previously sat firmly in Moscow's orbit, according to Zugec.
What's Next
Security teams should monitor for unusual traffic to trusted cloud services and scrutinize signed applications for unexpected behavior. As Chinese APTs continue to refine their "AI-assisted" development cycles, the industry can expect a surge in the volume of unique, modular malware families designed to maintain a persistent presence in strategically important regions.