Adversary Intelligence — 2026-08-21

Bitdefender Exposes Year-Long Chinese SilkParasite Espionage Campaign Targeting Central Asian Governments

BLUFSilkParasite's portable, multi-language toolkit and AI-accelerated development cycle compress the window between Central Asian targeting and adaptation against higher-value Western networks.

Bitdefender Labs published research on an espionage operation it designates SilkParasite, tracked since a suspicious infection was detected at an unnamed Central Asian government economic body in October 2025, identifying seven remote access tool families across four programming languages, five previously undocumented and named by Bitdefender: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT, alongside the previously known SpiceRAT and BloodAlchemy 12. The investigation logged roughly 65 infections, mostly in Asia, with DriveSilkRAT the most widely deployed strain; its hosts poll command files dropped into a shared Google Drive folder rather than a dedicated C2 server, masquerading as ordinary Google Drive traffic 1. Bitdefender recovered spearphishing lure documents impersonating ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan, plus one addressed to a Georgian entity, delivered via password-protected archives with macros that sideload malicious DLLs into six abused signed applications 13. The company assessed China-nexus attribution at medium confidence, citing Cisco Talos's prior linkage of SpiceRAT to SneakyChef, infrastructure tied to China Unicom's network, and BloodAlchemy's overlap with the ShadowPad/Deed RAT lineage tied to its earlier FamousSparrow reporting, alongside traces of AI-assisted development including leftover Go test functions, a placeholder key in GoginRAT, a literal "change_this_key" field in NodeEdgeRAT, and two AI-generated phishing lures 14.

Analysis
Bitdefender's China-nexus attribution rests at medium confidence on Cisco Talos's prior SpiceRAT-to-SneakyChef link, China Unicom-tied infrastructure, and BloodAlchemy's overlap with the ShadowPad/Deed RAT lineage from earlier FamousSparrow reporting; reporting otherwise rests on Bitdefender's own single technical disclosure, with other outlets adding only secondary color. The AI-assisted development traces embedded in disciplined, low-footprint tradecraft suggest China-nexus operators using AI to accelerate build cycles rather than generate malware wholesale, though the scaffolding and cheap AI-generated lures could equally reflect ordinary developer cost-cutting. The five newly named RAT families, Google Drive command channel, and DLL-sideloading delivery chain form a portable toolkit that can resurface against unrelated targets without reusing identifiable malware, and the focus on Central Asian economic-policy bodies tracks China's expansion into space long held by Russian influence.
4 sources
  1. SilkParasite: Tracking a China-Nexus APT Across Central Asia - Bitdefender
  2. SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs - The Hacker News
  3. SilkParasite Threatens Central Asian Orgs With Flurry of RATs - Dark Reading
  4. China's SilkParasite espionage operation targeting Central Asia with AI-assisted malware - The Record

View in full brief →

UNCLASSIFIED // OPEN SOURCE