HackMyIP
← Back to News
2026-08-19 Dark Reading

SilkParasite APT Deploys RATs Against Central Asian Organizations

APTPhishingThreat Intel

A Chinese-nexus advanced persistent threat (APT) group tracked as SilkParasite has launched a targeted spear-phishing campaign against government, diplomatic, and private-sector organizations across Central Asia, according to new research published by ESET. The campaign leverages weaponized documents and cloud-hosted payloads to deploy a suite of remote access trojans (RATs), giving operators persistent footholds in victim environments.

SilkParasite shares significant infrastructure and tooling overlap with FamousSparrow, an APT group previously linked to espionage operations across Asia, the Middle East, and Europe. Researchers identified overlaps in Cobalt Strike beacon configurations, PlugX loader variants, and the use of a custom backdoor internally dubbed SparrowDoor. The group exploited vulnerable public-facing applications as initial access vectors, deploying multi-stage droppers that ultimately delivered RATs capable of keystroke logging, file exfiltration, screen capture, and lateral movement via SMB and RDP.

What sets this campaign apart is its operational tempo. Within a single engagement window, SilkParasite deployed at least three distinct RAT families, rotating implants if one was detected or quarantined. The spear-phishing lures were highly tailored, referencing real regional policy events and diplomatic meetings to maximize credibility. Targets receiving these lures can verify exposure to known phishing infrastructure using an email breach checker, while security teams investigating suspicious network behavior should consider running a port scanner to identify unexpected listeners associated with RAT C2 callbacks.

The campaign underscores how China's state-aligned APT ecosystem continues to prioritize Central Asia as a strategic intelligence collection target, particularly around Belt and Road Initiative projects and regional security cooperation frameworks. Defenders are urged to enforce strict email filtering, disable macro execution by default, audit external-facing applications for known CVEs, and monitor for beaconing activity to cloud-hosted infrastructure. Indicators of compromise, including hashes and C2 domains, have been published for threat hunting teams to integrate into their detection pipelines.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →