Central Asian government bodies have been targeted in a cyberespionage operation using a compact but varied set of remote access tools.
The activity, tracked as SilkParasite, relied on convincing government-themed documents and trusted Windows programs to quietly place malware on victims’ systems.
The campaign appears designed for intelligence collection rather than widespread disruption. Its operators used spear-phishing emails with password-protected RAR archives, then used document macros to trigger malicious code.
The lures were tailored for organizations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and, in one case, Georgia.
Bitdefender analysts identified seven malware families in the operation, including five previously undocumented tools: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
The other two families were SpiceRAT and BloodAlchemy, showing that the operation blended new development with malware linked to earlier China-nexus activity.
The findings underline a growing risk for public-sector networks handling economic and diplomatic decisions.
Rather than using one noisy implant, the actors maintained several tools, changed their supporting files between builds, and used cloud services and normal-looking traffic to make investigation harder.
Bitdefender said in a report shared with Cyber Security News (CSN) that the cluster has a China-nexus link at medium confidence.
Researchers first detected the activity at a Central Asian government body around October 2025, then uncovered an operation that had been active for most of a year.
The evidence includes overlap with SpiceRAT, which Cisco Talos previously linked to SneakyChef, and infrastructure associated with China Unicom.
Bitdefender did not attribute SilkParasite to one specific named group, stressing that shared tools alone cannot establish control. That restraint is important for public reporting.
DriveSilkRAT formed the campaign’s backbone. It used a shared Google Drive folder for commands, downloaded plugins into memory, and returned collected data through the same service.
Researchers saw roughly 65 infection identifiers, although that figure is an upper bound because one computer can create more than one identifier through hardware fingerprinting.
The remaining malware families gave operators several ways to work inside a network. CookiETagRAT concealed commands in HTTP Cookie and ETag headers, while NomadRAT and GoginRAT fetched functions only when needed.
NodeEdgeRAT used a bundled Node.js runtime, and BloodAlchemy included capabilities for clipboard logging, keystroke capture, and running processes under another user’s session.
The delivery chain repeatedly abused DLL sideloading, where a legitimate signed application loads a harmful library placed beside it.
This same technique has appeared in an AsyncRAT sideloading campaign and makes simple file-name detections less reliable, because the visible program can be a genuine tool.
SilkParasite shows why a low number of infections should not be mistaken for a limited threat. The group’s modular tools kept the first-stage footprint small and allowed the operators to add features later.
Similar use of trusted cloud storage appeared in the C2Looper OneDrive malware update, reinforcing the need to examine suspicious activity within commonly allowed services.
Researchers found traces consistent with AI-assisted coding, including leftover test functions and placeholder encryption keys, but assessed that conclusion only at medium confidence.
The stronger point is operational discipline: the malware avoided conventional command servers in some cases, rotated artifacts, and used in-memory execution to reduce visible evidence.
Defenders should review signed applications running from unusual staging or temporary folders, especially when an unfamiliar DLL sits beside them.
Teams should also investigate outbound Google Drive connections that do not match user activity, inspect scheduled tasks, and build baselines that expose unusual links between processes and cloud services. Recent Central Asian government backdoors show that the region remains an active espionage target.
Users should treat both polished and poor-quality government-themed messages with caution. Some SilkParasite lures appeared deliberately cheap and AI-generated, meaning appearance alone is no longer a useful measure of trust.
Organizations should limit macros, verify unexpected password-protected archives through a second channel, and train staff to report suspicious messages before opening attachments.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | evo[.]hoster-kg[.]com | NodeEdgeRAT command-and-control domain impersonating the Kyrgyz hosting provider hoster.kg |
| Scheduled task | SysEdgeUpdateTaskMachineCore | NodeEdgeRAT persistence task presented as a Microsoft Edge update job |
| Persistence entry | fl_bridge | BloodAlchemy persistence artifact named in the report |
| Directory | C:\ProgramData\USOShared\Logs\ | SpiceRAT copy location used before creating a recurring scheduled task |
| Process name | avp.exe | Security product process checked by the delivery macro before execution |
| Sideloaded host / DLL | ebook-edit.exe / calibre-launcher.dll | Calibre application and malicious SpiceRAT loader DLL, also tracked as HelpLoader |
| Sideloaded host / DLL | FineReader.exe / dsp_ippv2_x64.dll | ABBYY FineReader and malicious BloodAlchemy DLL |
| Sideloaded host / DLL | emlproui.exe / scansts.dll | Quick Heal executable and malicious NomadRAT DLL |
| Sideloaded host / DLL | MpDefenderCoreService.exe / mpclient.dll | Windows Defender service executable and malicious C++ DriveSilkRAT DLL |
| Sideloaded host / DLL | Mp3tag.exe / tak_deco_lib.dll | Mp3tag executable and malicious CookiETagRAT DLL |
| Loader DLL | mscorsvc.dll | GoginRAT loader DLL used to decrypt and launch the Go-based orchestrator |
| Hardcoded key | 0123456789abcdef | Sequential AES key embedded in GoginRAT |
| Configuration value | change_this_key | Placeholder encryption-key value found in NodeEdgeRAT configuration |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as…
Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on…
More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…
Threat actors are increasingly abusing overlooked Active Directory service principal name (SPN) misconfigurations to launch…
A newly disclosed vulnerability in cPanel and WHM, the widely used web hosting control panel…
PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used…