Friday , August 21 2026
Asian government

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of remote access tools. The action called SilkParasite used fake government documents and trusted Windows programs to secretly install malware on victims’ computers.

The campaign seems to be aimed at intelligence gathering rather than causing widespread disruption. Its operators employed spear-phishing emails that contained password-protected RAR archives and then utilized document macros to activate malicious code. The lures were specifically crafted for organizations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and, in one instance, Georgia.

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

500+ critical infrastructure hit by Medusa ransomware

Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa...
Read More
500+ critical infrastructure hit by Medusa ransomware

Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could...
Read More
Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

Bitdefender found seven types of malware in the operation. Five of these were new tools: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two families were SpiceRAT and BloodAlchemy. This shows that the operation mixed new developments with malware connected to past activities in China.

The results show a rising danger for public networks that deal with economic and diplomatic choices.

The attackers used multiple tools instead of one main one. They changed their files for each version and used cloud services along with regular-looking traffic to make it harder to investigate.

Bitdefender has medium confidence that the cluster has a China-nexus link at medium confidence.

China-Linked Spy Campaign Uses Five New Malware Families

Researchers found the activity at a Central Asian government agency around October 2025. They discovered an operation that had been going on for nearly a year. The proof includes connections to SpiceRAT, which Cisco Talos had earlier linked to SneakyChef, and systems tied to China Unicom.

Bitdefender did not link SilkParasite to a specific group. They said that just having the same tools does not prove control. This caution is important for public reports.

DriveSilkRAT was the main part of the campaign. It used a Google Drive folder to send commands, downloaded plugins into memory, and sent back data using the same service.

Researchers found about 65 infection identifiers. This number is a bit high because one computer can make more than one identifier through hardware fingerprinting.

The other malware types let users operate within a network. CookiETagRAT hid commands in HTTP Cookie and ETag headers, while NomadRAT and GoginRAT got functions only when necessary.

NodeEdgeRAT used a built-in Node.js runtime, and BloodAlchemy had features for clipboard logging, capturing keystrokes, and running processes in another user’s session.

The delivery chain often misused DLL sideloading. This is when a real signed app opens a harmful file next to it.

This technique has been used in an AsyncRAT sideloading campaign. It makes it harder to detect by file name because the program shown can be a real tool.

Defenders Should Hunt Behavior

SilkParasite explains that having few infections does not mean there is no threat. Their flexible tools kept the initial impact small and let the users add new features later.

The C2Looper OneDrive malware update also used trusted cloud storage. This shows we need to check for strange behavior in popular services.

Researchers found signs of AI-helped coding, like leftover test functions and dummy encryption keys, but they only believed this conclusion with medium certainty.

The main strength is operational discipline: the malware skipped regular command servers at times, changed its tools, and ran directly in memory to leave less evidence.

Defenders need to check signed applications that come from strange staging or temporary folders, especially if there is an unknown DLL next to them.

Teams need to look into Google Drive connections that don’t match what users are doing. They should check scheduled tasks and create baselines to find strange links between processes and cloud services. Recent backdoors in Central Asian governments show that this area is still a target for spying.

Check Also

Bangladesh Military

DoNot (APT-C-35) Targeting Bangladesh Military Personnel

Bangladesh’s military and defense system is actively under targeted attack linked to DoNot Team, or …