HackMyIP
← Back to News
2026-08-19 The Hacker News

SilkParasite Espionage Campaign Hits Central Asia With 5 New RATs

APTMalwareThreat Intel

A previously undocumented cyber-espionage operation dubbed SilkParasite has been targeting government bodies across Central Asia with seven remote access tool (RAT) families—five of which have never been publicly reported. Bitdefender Labs, which disclosed the cluster, identified the new strains as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The Romanian vendor assessed the group as a China-nexus threat cluster with medium confidence, noting that SilkParasite becomes the third prominent actor to hit the region in recent years, following UAC-0063 and FamousSparrow.

What sets SilkParasite apart is the presence of AI-assisted development woven through otherwise expert-level code—distinct from fully AI-generated malware. Researchers flagged the most obvious tell in a phishing lure that was indubitably AI-generated, and possibly left deliberately to muddy attribution. The operation's tooling still bears the hallmarks of professional, human-built espionage software: a backdoor called BLOODALCHEMY (an updated Deed RAT, itself a successor to ShadowPad and a descendant of PlugX—both staples of Chinese state-aligned operators), plus an updated variant of SpiceRAT linked to a separate Chinese-speaking actor dubbed SneakyChef. Organizations concerned about exposure can validate their own perimeter hygiene with a quick port scanner and review egress points with a VPN/proxy detector.

The kill chain begins with spear-phishing emails carrying password-protected RAR archives, with the password conveniently included in the message body. Opening the malicious Microsoft Office document inside triggers a macro that initiates a DLL sideloading sequence using a legitimate, vulnerable binary to drop the first-stage payload. BLOODALCHEMY supports basic commands for host enumeration, binary and loader overwrite, and self-uninstallation, while SpiceRAT handles download-and-execute functionality. Recipients of suspicious attachments are advised to verify document origins and test credential strength with a password checker before reusing archive passphrases.

The regionally tailored lures were crafted to appear relevant to Central Asian government entities, reinforcing the assessment of a targeted intelligence-gathering mission. With espionage-grade tooling now augmented by AI-assisted workflows, defenders in the public sector should prioritize detection of DLL sideloading, anomalous Office macro behavior, and unusual outbound connections—a posture reinforced by routine SSL/TLS checks on web-facing government services and broader exposure reviews using a privacy checkup.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →