VMTech
Discuss a project

SilkParasite campaign uses five new RATs against Central Asian governments

SilkParasite campaign uses five new RATs against Central Asian governments

Bitdefender Labs has identified a previously unreported cyber-espionage operation, SilkParasite, targeting government bodies in Central Asia with seven remote access tool families. Five of the implants had not been documented before: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT. The researchers observed roughly 65 DriveSilkRAT infections, most of them in Asia.

First discovered in late 2025, SilkParasite is assessed with medium confidence to be a China-nexus threat cluster. The campaign uses password-protected RAR archives containing malicious Microsoft Office documents, likely sent through spear-phishing. The archive password is supplied in the email body, and opening the document launches a macro that begins a DLL sideloading sequence for the first-stage payload.

Regional lures and established malware links

Recovered lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan, including documents impersonating specific ministries. A separate document recovered from a public malware-sharing platform was addressed to a Georgian government entity. The macro also checks whether Kaspersky antivirus is installed and running before execution, a detail Bitdefender linked to the product's prevalence in the region.

Several elements support the China-nexus assessment. The operation uses BLOODALCHEMY, an updated version of Deed RAT, which followed ShadowPad. ShadowPad evolved from PlugX, and both have been widely used by Chinese hacking groups. SilkParasite also deploys an updated SpiceRAT, a tool attributed to the Chinese-speaking actor known as SneakyChef. The wider regional pressure is reflected in ClickFix chains and AI agent incidents, where attacks involving ClickFix chains and AI agents show how varied initial-access and operator techniques can be.

Plugin-based implants reduce the visible footprint

Almost every SilkParasite tool uses a plugin-oriented architecture. That lets operators add functions selectively, adapt payloads to a victim environment and update components without replacing their underlying foundations. The seven implants span .NET, C++, Go and JavaScript, with DLL sideloading as the principal delivery vector.

In this technique, the attackers bring their own legitimately signed application and place a rogue DLL beside it under a name the application expects. The trusted program then loads the malicious library. DriveSilkRAT uses Google Drive as command-and-control infrastructure, polling a folder for tasks, running them through an in-memory .NET plugin system and returning results to the same folder. Its 12 plugins support process listings, system and network enumeration, file management and command execution.

CookiETagRAT receives commands through HTTP Cookie and ETag response headers. NomadRAT has an orchestrator, a separate C2 transmitter and plugins fetched by numeric identifier only when needed. GoginRAT follows a similar design in Go, while NodeEdgeRAT delivers command execution, file management and file transfer in a single JavaScript script.

Detection should focus on behavioural relationships

Bitdefender found signs of AI-assisted development in GoginRAT and NodeEdgeRAT, including weak hard-coded encryption-key values, and in the shared architecture of NomadRAT and GoginRAT. The company distinguished this from AI-generated malware, describing otherwise professional espionage tooling likely accelerated by AI-assisted workflows.

For defenders, Bitdefender identifies the most consistent signal as DLL sideloading: a legitimately signed application loading a library placed beside it while running from an unusual location. Businesses should therefore baseline normal process and network-service relationships and investigate suspicious signed executable and adjacent DLL pairings, particularly where low-footprint plugins use legitimate cloud services.

#cybersecurity#threatintelligence#malware#dllsideloading
Open analytics
On the site 0 views
min read 4 19.08.2026
Instagram

SilkParasite campaign uses five new RATs against Central Asian governments

Open the post on Instagram ↗