Bitdefender Exposes Year-Long Chinese SilkParasite Espionage Campaign Targeting Central Asian Governments
Bitdefender Labs published research on an espionage operation it designates SilkParasite, tracked since a suspicious infection was detected at an unnamed Central Asian government economic body in October 2025, identifying seven remote access tool families across four programming languages, five previously undocumented and named by Bitdefender: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT, alongside the previously known SpiceRAT and BloodAlchemy
Bitdefender's China-nexus attribution rests at medium confidence on Cisco Talos's prior SpiceRAT-to-SneakyChef link, China Unicom-tied infrastructure, and BloodAlchemy's overlap with the ShadowPad/Deed RAT lineage from earlier FamousSparrow reporting; reporting otherwise rests on Bitdefender's own single technical disclosure, with other outlets adding only secondary color. The AI-assisted development traces embedded in disciplined, low-footprint tradecraft suggest China-nexus operators using AI to accelerate build cycles rather than generate malware wholesale, though the scaffolding and cheap AI-generated lures could equally reflect ordinary developer cost-cutting. The five newly named RAT families, Google Drive command channel, and DLL-sideloading delivery chain form a portable toolkit that can resurface against unrelated targets without reusing identifiable malware, and the focus on Central Asian economic-policy bodies tracks China's expansion into space long held by Russian influence.
4 sources
- SilkParasite: Tracking a China-Nexus APT Across Central Asia -
Bitdefender - SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs -
The Hacker News - SilkParasite Threatens Central Asian Orgs With Flurry of RATs -
Dark Reading - China's SilkParasite espionage operation targeting Central Asia with AI-assisted malware -
The Record