mimile
Back to feed

Bitdefender Labs links SilkParasite to Central Asia government espionage

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Bitdefender Labs links SilkParasite to Central Asia government espionage

Bitdefender Labs attributed a cyber-espionage campaign targeting Central Asian governments to a Chinese-nexus group called SilkParasite in a report published Aug. 19. The campaign uses spear-phishing emails to deploy seven remote-access Trojan families against government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Bitdefender technical solutions director Martin Zugec linked the operation to the previously tracked FamousSparrow group and the ShadowPad ecosystem.

Key Facts

  • Bitdefender Labs began tracking SilkParasite in late 2025 after detecting an infection at a Central Asian government body involved in economic decision-making.
  • The campaign targets government entities in five Central Asian countries — Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan — using spear-phishing lures with regionally tailored Office documents.
  • Seven malware families were observed; five previously undocumented families were named DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT, while the other two are the previously documented SpiceRAT and BloodAlchemy.
  • Bitdefender technical solutions director Martin Zugec said the activity has direct links to the previously tracked FamousSparrow group and indirect links to the broader ShadowPad-linked ecosystem.

Campaign Scope and Targets

Bitdefender Labs began tracking SilkParasite in late 2025 after an infection at a Central Asian government body involved in economic decision-making. The group targets government entities in five Central Asian countries: Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Spear-phishing emails carry regionally tailored Office documents, sometimes inside password-protected RAR archives. Attackers include archive passwords in the accompanying email to evade security gateways and automated analysis.

Malware Families and AI Traces

Seven malware families were detected in the campaign. Five were previously undocumented and named by Bitdefender as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The remaining two families are the previously documented SpiceRAT and BloodAlchemy. The toolset is small, modular, and professionally engineered, with traces of AI-assisted development.

Links to Chinese Espionage

SilkParasite, tracked by Bitdefender since late 2025, targets five Central Asian countries and has direct links to the previously tracked FamousSparrow group. Bitdefender technical solutions director Martin Zugec said the activity also has indirect links to the broader ShadowPad-linked ecosystem. Zugec said cyber espionage follows influence, and SilkParasite reflects China's move into a space left by receding Russian influence across Central Asia.

1 source

Bitdefender Labs links SilkParasite to Central Asia government espionage