China-Linked SilkParasite Campaign Uses AI Against Central Asian Governments, Bitdefender Says
This digest was compiled by AI from multiple sources — links to the originals are below.

Bitdefender researchers on Aug. 18 identified a China-linked remote-access campaign, dubbed SilkParasite, that used seven malware families against government agencies in five Central Asian countries during 2025. The malware shows traces of AI-assisted development in otherwise hand-built code. Separately, Dream reported on Aug. 12 that an attack on Asian government entities used up to eight AI agents, and Taiwan's Ministry of Digital Affairs said the description matched an incident it responded to.
Key Facts
- Bitdefender identified the SilkParasite campaign, which used seven malware families — five previously unknown — against government agencies across Central Asia for almost a year in 2025.
- The SilkParasite toolset carries traces of AI-assisted development inside otherwise professionally engineered, hand-built code.
- Dream reported on Aug. 12 that attackers used up to eight simultaneously operated AI agents to conduct reconnaissance, exploit vulnerabilities and refine successive attacks on government entities in Asia.
- Taiwan's Ministry of Digital Affairs said the Dream-described incident matched an attack it responded to that used 'AI agents like OpenClaw.'
- SilkParasite lure documents impersonated government bodies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan, and two lures were generated by AI.
SilkParasite Campaign
Bitdefender researchers Marius Baciu, Gheorghe Schipor and Victor Vrabie described the SilkParasite toolset as small, modular and professionally engineered, with traces of AI-assisted development. The campaign is the third cyber operation in the region observed by Bitdefender, following UAC-0063, which targeted Central Asian and European governments, and FamousSparrow, which targeted Azerbaijani oil and gas infrastructure. Initial access came through malicious Microsoft Office files likely delivered by spear-phishing emails, with some lure documents packaged in password-protected RAR archives and passwords supplied in the email body. The documents ran a macro that dropped a signed-application sideloading chain and launched the first-stage payload, and the script adjusted its behavior to evade antivirus tools common among the targets. Two of the phishing lures were generated with AI, including a poorly made fake energy-sector organization and a fake cloud-computing provider advertising GPU services.
AI Agents in APAC
Dream reported on Aug. 12 that an attack on government entities in Asia used up to eight simultaneously operated AI agents for reconnaissance, vulnerability assessment, network exploitation and iterative improvement of successive attacks. The company did not attribute the attack to a specific actor but said strong evidence indicated the attackers spoke simplified Chinese, typically a sign of speakers from mainland China. Taiwan's Ministry of Digital Affairs issued a statement the following day describing its response to an attack matching much of Dream's description, including the use of 'AI agents like OpenClaw.' Amir Becker, chief business and strategy officer at Dream and a former commander of Israel's 8200 Unit, said the incident should be a warning that fully autonomous attacks could be used against major targets.
2 sources
China-Linked SilkParasite Campaign Uses AI Against Central Asian Governments, Bitdefender Says



