< Back to situation

[REVISION HISTORY]

Chinese-nexus cyber espionage in Central Asia and Azerbaijan

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-20 01:48 UTC → 2026-08-23 07:48 UTC · added removed

Since early 2025, a series of cyber espionage campaigns attributed to Chinese-nexus threat actors has targeted government institutions in Central Asia and surrounding regions. Initial activity involved the deployment of heavily obfuscated backdoors known as OctLurk and SilkLurk, alongside a proxy tool called LurkProxy. These tools were used to target ministries, law enforcement, and health agencies in countries including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The malware was capable of credential dumping, keylogging, and remote file access. The campaign has since evolved into an operation identified as SilkParasite. This phase utilizes a sophisticated arsenal of seven remote access tool (RAT) families, including five previously undocumented tools such as DriveSilkRAT DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. This operation has expanded its scope to include the Azerbaijani energy sector, specifically targeting oil and gas infrastructure. Analysts note a strategic shift toward cross-platform capabilities, with payloads designed for Windows, Linux, and macOS to compromise IoT and OT gateways, potentially allowing lateral movement into critical industrial control systems. Recent analysis links the campaign to the Chinese-nexus group FamousSparrow. Researchers have observed the professional use of artificial intelligence to streamline malware development and create phishing lures. One reported tactic involved using low-quality AI-generated content in phishing emails to blend in with common digital noise. To evade detection, attackers have routed command-and-control communications through legitimate cloud services like Google Drive. While the campaign targets various Central Asian nations, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, evidence also suggests targeting in Georgia. Unlike financially motivated ransomware, SilkParasite focuses on the long-term collection of strategic intelligence.

Versions

  1. 2026-08-23 07:48 UTC Chinese-nexus cyber espionage in Central Asia and Azerbaijan
  2. 2026-08-20 01:48 UTC Chinese-nexus cyber espionage in Central Asia and Azerbaijan

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.