Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of remote access tools. The action called SilkParasite used fake government documents and trusted Windows programs to secretly install malware on victims’ computers.
The campaign seems to be aimed at intelligence gathering rather than causing widespread disruption. Its operators employed spear-phishing emails that contained password-protected RAR archives and then utilized document macros to activate malicious code. The lures were specifically crafted for organizations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and, in one instance, Georgia.
Bitdefender found seven types of malware in the operation. Five of these were new tools: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two families were SpiceRAT and BloodAlchemy. This shows that the operation mixed new developments with malware connected to past activities in China.
The results show a rising danger for public networks that deal with economic and diplomatic choices.
The attackers used multiple tools instead of one main one. They changed their files for each version and used cloud services along with regular-looking traffic to make it harder to investigate.
Bitdefender has medium confidence that the cluster has a China-nexus link at medium confidence.
China-Linked Spy Campaign Uses Five New Malware Families
Researchers found the activity at a Central Asian government agency around October 2025. They discovered an operation that had been going on for nearly a year. The proof includes connections to SpiceRAT, which Cisco Talos had earlier linked to SneakyChef, and systems tied to China Unicom.
Bitdefender did not link SilkParasite to a specific group. They said that just having the same tools does not prove control. This caution is important for public reports.
DriveSilkRAT was the main part of the campaign. It used a Google Drive folder to send commands, downloaded plugins into memory, and sent back data using the same service.
Researchers found about 65 infection identifiers. This number is a bit high because one computer can make more than one identifier through hardware fingerprinting.
The other malware types let users operate within a network. CookiETagRAT hid commands in HTTP Cookie and ETag headers, while NomadRAT and GoginRAT got functions only when necessary.
NodeEdgeRAT used a built-in Node.js runtime, and BloodAlchemy had features for clipboard logging, capturing keystrokes, and running processes in another user’s session.
The delivery chain often misused DLL sideloading. This is when a real signed app opens a harmful file next to it.
This technique has been used in an AsyncRAT sideloading campaign. It makes it harder to detect by file name because the program shown can be a real tool.
Defenders Should Hunt Behavior
SilkParasite explains that having few infections does not mean there is no threat. Their flexible tools kept the initial impact small and let the users add new features later.
The C2Looper OneDrive malware update also used trusted cloud storage. This shows we need to check for strange behavior in popular services.
Researchers found signs of AI-helped coding, like leftover test functions and dummy encryption keys, but they only believed this conclusion with medium certainty.
The main strength is operational discipline: the malware skipped regular command servers at times, changed its tools, and ran directly in memory to leave less evidence.
Defenders need to check signed applications that come from strange staging or temporary folders, especially if there is an unknown DLL next to them.
Teams need to look into Google Drive connections that don’t match what users are doing. They should check scheduled tasks and create baselines to find strange links between processes and cloud services. Recent backdoors in Central Asian governments show that this area is still a target for spying.
InfoSecBulletin Cybersecurity for mankind
