started · updated
SilkParasite campaign targets Central Asian governments
Security researchers have identified a sophisticated cyber espionage campaign known as ‘SilkParasite’ that has been targeting government institutions in Central Asia for approximately one year. The campaign primarily focuses on government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, with evidence of targeting in Georgia.
According to reports from Bitdefender, the attackers utilized seven different families of Remote Access Trojans (RATs), five of which were previously undocumented. The intrusion method typically involves spear-phishing emails containing password-protected RAR archives. To avoid detection, the attackers routed command-and-control communications through legitimate cloud services like Google Drive.
A notable technical aspect of the campaign is the professional use of artificial intelligence. Analysts noted traces of AI-assisted development within the code, which appears to be used to accelerate the attackers' workflow rather than generating low-quality, fully automated malware. One phishing lure was reportedly intentionally designed with low-quality AI generation to blend into the increasing volume of AI-generated daily communications.
Industry analysts from Dark Web Intelligence have categorized SilkParasite as a ‘China-nexus’ campaign. This assessment is based on the use of SpiceRAT and connections to China Unicom infrastructure. Unlike ransomware attacks driven by financial gain, SilkParasite focuses on the long-term, undetected collection of strategic intelligence.