Actor Profile
SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster. The actor targets government bodies across Central Asia (Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia). Attribution to China is supported by use of BLOODALCHEMY (an updated Deed RAT variant, itself descended from ShadowPad/PlugX) and an updated version of SpiceRAT linked to the Chinese-speaking SneakyChef actor. The operation is notable for exhibiting professional espionage tooling developed by human operators with traces of AI-assisted development to streamline processes, rather than purely AI-generated malware. The actor demonstrates sophisticated OPSEC including region-specific lures and anti-detection checks for Kaspersky AV.
TTPs (Tactics, Techniques, Procedures)
Initial access via spear-phishing emails with password-protected RAR archives containing malicious Microsoft Office documents (T1566.001). Macros trigger DLL sideloading sequences (T1574.002) using legitimate signed binaries with rogue DLLs to deploy first-stage payloads. The operation deploys seven RAT families across four programming languages (.NET, C++, Go, JavaScript) with plugin-oriented architectures for modular capabilities. C2 techniques include Google Drive API abuse (DriveSilkRAT), HTTP Cookie/ETag header manipulation (CookiETagRAT), and dedicated transmitter libraries (NomadRAT, GoginRAT). Capabilities span process enumeration, system/network reconnaissance, file management, command execution, and file transfer. Defense evasion includes checks for Kaspersky AV presence before execution and selective payload deployment to minimize detection footprint.
Targets & Patterns
SilkParasite exclusively targets government entities in Central Asia, with confirmed targeting of Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia. Lures were regionally tailored and crafted to appear relevant to specific government ministries in these countries. The targeting pattern aligns with strategic intelligence collection objectives typical of China-nexus espionage operations in the region. Bitdefender observed approximately 65 DriveSilkRAT infections, predominantly in Asia. The focus on Central Asian governments suggests geopolitical and strategic intelligence gathering motivations, consistent with regional influence operations. The actor demonstrates deep understanding of the target environment, including knowledge that Kaspersky AV is prevalent in the region.
Historical Context
SilkParasite represents the third prominent threat actor targeting Central Asia in recent years, following UAC-0063 and FamousSparrow. The operation's use of BLOODALCHEMY links it to REF5961 activity documented by Elastic Security Labs in October 2023, which targeted government organizations in Southern and Southeast Asia. BLOODALCHEMY itself is an evolution of Deed RAT, which descended from ShadowPad (itself an evolution of PlugX) - malware families widely used by Chinese APT groups. The use of updated SpiceRAT connects the operation to the Chinese-speaking SneakyChef actor. This represents a continuation of sustained Chinese cyber espionage interest in Central Asian governments, with SilkParasite deploying more sophisticated, modular tooling than many predecessors.
Defensive Recommendations
- Monitor for DLL sideloading activity (T1574.002) by detecting legitimate signed binaries loading unexpected DLLs from non-standard paths, particularly focusing on process creation with suspicious parent-child relationships
- Implement behavioral detection for Google Drive API abuse as C2 by monitoring for unusual patterns of file polling, uploads to specific folders from non-browser processes, and high-frequency Drive API calls from system processes
- Detect macro-based initial access (T1566.001) by blocking or heavily scrutinizing Office documents with macros, especially those delivered in password-protected archives, and enable AMSI logging for macro execution
- Hunt for HTTP Cookie/ETag header anomalies in web traffic that may indicate CookiETagRAT C2 communication, focusing on responses with unusually large or encoded Cookie/ETag values to non-browser processes
- Deploy YARA rules targeting the plugin-oriented architecture patterns across .NET, C++, Go, and JavaScript implants, including detection of hard-coded test values like AES key '0123456789abcdef' and configuration fields set to 'change_this_key' that indicate AI-assisted development artifacts
---
# Geopolitical Context
Geopolitical Context
The SilkParasite operation, assessed with medium confidence to be a China-nexus threat cluster, represents the third significant espionage campaign targeting Central Asian governments in recent years, following UAC-0063 and FamousSparrow. The campaign's focus on government entities across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan aligns with broader Chinese strategic interests in the region, particularly within the context of Belt and Road Initiative engagement and competition for influence in the former Soviet space. The use of BLOODALCHEMY—an evolution of Deed RAT, ShadowPad, and PlugX—and an updated version of SpiceRAT (linked to the Chinese-speaking SneakyChef actor) provides technical lineage consistent with established Chinese cyber espionage tooling. The operation's sophistication, including regionally tailored lures impersonating specific ministries and checks for Kaspersky antivirus (prevalent in the region), suggests a well-resourced actor with detailed operational planning capabilities. Notably, the campaign exhibits what researchers describe as AI-assisted development within otherwise expert code, potentially representing an emerging trend in state-sponsored cyber operations where artificial intelligence streamlines professional malware development rather than replacing human expertise.
State Actor Alignment
SilkParasite is assessed with medium confidence to be linked to Chinese state interests. Attribution indicators include: (1) deployment of BLOODALCHEMY, previously associated with REF5961 operations against government organizations in Southern and Southeast Asia; (2) use of an updated SpiceRAT variant attributed to Chinese-speaking threat actor SneakyChef; (3) technical lineage connecting to widely-used Chinese espionage tools including ShadowPad and PlugX; and (4) targeting patterns consistent with Chinese strategic intelligence priorities in Central Asia. The campaign's professional tradecraft, modular plugin architecture across seven RAT families, and regionally customized social engineering suggest a well-resourced operation consistent with state-sponsored capabilities. While no formal government attribution has been issued, the technical and operational characteristics align with known Chinese cyber espionage methodologies.
Business Impacty pro region
The campaign underscores Central Asia's position as contested cyber terrain where multiple state actors pursue intelligence collection against government institutions. For the targeted states—Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan—the operation highlights persistent vulnerabilities in government networks and the challenge of defending against sophisticated, multi-tool espionage campaigns. The inclusion of a Georgian government entity among the targets suggests potential scope expansion beyond Central Asia proper. For European security stakeholders, SilkParasite illustrates the spillover risks from great power competition in adjacent regions, particularly as Central Asian states navigate relationships with China, Russia, and Western partners. The campaign's technical sophistication and apparent AI-assisted development may signal an evolution in state-sponsored cyber capabilities that could be applied to other regions. The operation also reinforces the strategic importance of Central Asia as an intelligence target, where economic corridors, energy resources, and geopolitical alignment remain contested among major powers.
Forecast
If SilkParasite maintains operational security and continues to refine its AI-assisted development processes, the campaign is likely to persist against Central Asian government targets in the near to medium term, with potential expansion to additional ministries and agencies. The modular architecture of the deployed RATs suggests the operators can adapt quickly to defensive measures without replacing core infrastructure, which may enable sustained access even if individual components are detected. If regional governments enhance detection capabilities and information sharing—particularly regarding the specific DLL sideloading techniques and C2 patterns documented in this campaign—the operational lifespan of current tooling may be reduced, though the threat actor appears capable of developing replacement capabilities. The apparent integration of AI assistance into professional malware development workflows may become more prevalent across state-sponsored operations if it proves effective at accelerating development cycles while maintaining operational security. If attribution confidence increases or if the campaign's scope expands to include targets in Europe or other Western-aligned regions, diplomatic responses and potential sanctions discussions may follow, though Central Asia's complex geopolitical positioning may limit coordinated responses.
