Monday , October 5 2026
Asian government

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of remote access tools. The action called SilkParasite used fake government documents and trusted Windows programs to secretly install malware on victims’ computers.

The campaign seems to be aimed at intelligence gathering rather than causing widespread disruption. Its operators employed spear-phishing emails that contained password-protected RAR archives and then utilized document macros to activate malicious code. The lures were specifically crafted for organizations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and, in one instance, Georgia.

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Bitdefender found seven types of malware in the operation. Five of these were new tools: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two families were SpiceRAT and BloodAlchemy. This shows that the operation mixed new developments with malware connected to past activities in China.

The results show a rising danger for public networks that deal with economic and diplomatic choices.

The attackers used multiple tools instead of one main one. They changed their files for each version and used cloud services along with regular-looking traffic to make it harder to investigate.

Bitdefender has medium confidence that the cluster has a China-nexus link at medium confidence.

China-Linked Spy Campaign Uses Five New Malware Families

Researchers found the activity at a Central Asian government agency around October 2025. They discovered an operation that had been going on for nearly a year. The proof includes connections to SpiceRAT, which Cisco Talos had earlier linked to SneakyChef, and systems tied to China Unicom.

Bitdefender did not link SilkParasite to a specific group. They said that just having the same tools does not prove control. This caution is important for public reports.

DriveSilkRAT was the main part of the campaign. It used a Google Drive folder to send commands, downloaded plugins into memory, and sent back data using the same service.

Researchers found about 65 infection identifiers. This number is a bit high because one computer can make more than one identifier through hardware fingerprinting.

The other malware types let users operate within a network. CookiETagRAT hid commands in HTTP Cookie and ETag headers, while NomadRAT and GoginRAT got functions only when necessary.

NodeEdgeRAT used a built-in Node.js runtime, and BloodAlchemy had features for clipboard logging, capturing keystrokes, and running processes in another user’s session.

The delivery chain often misused DLL sideloading. This is when a real signed app opens a harmful file next to it.

This technique has been used in an AsyncRAT sideloading campaign. It makes it harder to detect by file name because the program shown can be a real tool.

Defenders Should Hunt Behavior

SilkParasite explains that having few infections does not mean there is no threat. Their flexible tools kept the initial impact small and let the users add new features later.

The C2Looper OneDrive malware update also used trusted cloud storage. This shows we need to check for strange behavior in popular services.

Researchers found signs of AI-helped coding, like leftover test functions and dummy encryption keys, but they only believed this conclusion with medium certainty.

The main strength is operational discipline: the malware skipped regular command servers at times, changed its tools, and ran directly in memory to leave less evidence.

Defenders need to check signed applications that come from strange staging or temporary folders, especially if there is an unknown DLL next to them.

Teams need to look into Google Drive connections that don’t match what users are doing. They should check scheduled tasks and create baselines to find strange links between processes and cloud services. Recent backdoors in Central Asian governments show that this area is still a target for spying.

Check Also

CISA

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw …