Researchers at Bitdefender have published a report on a sophisticated cyberespionage campaign dubbed SilkParasite. The operation, which began as early as October 2025, targets government organizations in Central Asia, with a focus on entities involved in economic policy. Bitdefender attributes the campaign with medium confidence to a China-nexus threat actor. The attackers employ a custom, modular malware arsenal, including five previously unknown Remote Access Trojans (RATs). A key feature of the campaign is the use of legitimate cloud services, specifically Google Drive, for command and control (C2) communications, making the malicious traffic difficult to distinguish from benign activity.
The SilkParasite campaign is characterized by its stealth and use of advanced, custom tooling. The primary targets are government bodies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. The goal appears to be long-term espionage to gather intelligence on economic matters.
Initial access is achieved via spear-phishing emails containing password-protected RAR archives. Inside the archives are malicious Microsoft Office documents crafted to be relevant to the target ministry or official. When the victim opens the document, a multi-stage infection process begins, ultimately deploying one of several RATs.
The attackers use seven different RAT families, with five being newly discovered: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The malware shows links to known China-nexus toolsets like ShadowPad and Deed RAT, suggesting a connection to established APT actors.
The campaign's infection chain is designed for stealth and persistence.
T1566.001 - Spearphishing Attachment. The use of password-protected archives helps bypass initial email gateway scans.T1574.002 - DLL Side-Loading, where a legitimate application is tricked into loading a malicious DLL.DriveSilkRAT. The malware uses the Google Drive API to download new plugins and receive commands, which are stored in files within the attacker's cloud storage. This is a form of T1071.001 - Web Protocols combined with T1102 - Web Service to hide C2 traffic within legitimate, encrypted web traffic.T1056 - Input Capture, T1113 - Screen Capture).T1566.001 - Spearphishing AttachmentT1574.002 - DLL Side-LoadingT1071.001 - Web ProtocolsT1102 - Web ServiceT1056 - Input CaptureT1113 - Screen CaptureT1041 - Exfiltration Over C2 ChannelThe SilkParasite campaign represents a significant threat to the national security and economic stability of the targeted Central Asian nations. By infiltrating government bodies responsible for economic decisions, the threat actor can gain advance knowledge of policy changes, trade negotiations, and other sensitive information. This intelligence can provide a significant economic and geopolitical advantage. The use of stealthy, custom malware and legitimate services for C2 makes detection and attribution challenging, allowing the campaign to persist for long periods.
No specific file hashes, C2 domains, or IP addresses were provided in the source articles.
Security teams can hunt for signs of SilkParasite activity by looking for:
drive.google.com or googleapis.com from server-side processes or unexpected applications.rundll32.exe executing an exported function from a DLL in a non-standard directory.WINWORD.EXE or EXCEL.EXE.Use application control or endpoint protection rules to block legitimate applications from loading untrusted DLLs.
Train high-value targets to identify and report sophisticated spear-phishing attempts.
Monitor or block traffic to cloud storage services from sensitive systems to disrupt C2 channels.
SilkParasite campaign is first detected by Bitdefender.
Bitdefender publishes its research on the SilkParasite campaign.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.