< Back to all clusters
[TECHNOLOGY] · Azerbaijan · 5 sources

started · updated

SilkParasite cyber campaign targets Central Asian governments and Azerbaijani energy sector

A cyber espionage operation known as SilkParasite is targeting government bodies in Central Asia and the Azerbaijani energy sector. Attributed with medium confidence to a China-nexus threat cluster, the campaign utilizes a sophisticated arsenal of seven remote access tool (RAT) families, including five previously undocumented tools: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.

Technical analysis from Bitdefender Labs indicates that while the malware code appears to be developed by professional human operators, AI is likely being used to streamline development and create phishing lures. The operation is linked to the Chinese-nexus threat group FamousSparrow, which is currently conducting high-intensity espionage against Azerbaijan’s oil and gas sector.

The campaign demonstrates a strategic shift toward cross-platform capabilities, deploying payloads designed for Windows, Linux, and macOS to compromise various environments, including IoT and OT gateways. This poses a significant risk of lateral movement from corporate IT networks into critical industrial control systems, threatening the stability of regional energy infrastructure.

Entities

Azerbaijan · Bitdefender Labs · FamousSparrow · SilkParasite