Cyberwarfare / Nation-State Attacks,
Fraud Management & Cybercrime
SilkParasite Deployed Against Central Asian Governments

Researchers have recently uncovered a sophisticated cyber campaign known as SilkParasite, which has targeted government agencies across Central Asia. This campaign, attributed to a state-sponsored group linked to China, employed a set of remote access Trojans (RATs) that demonstrate a blend of traditional malware development and advanced artificial intelligence technologies. The tools deployed in this campaign were not generated purely by AI; rather, they reflected an amalgamation of manual coding complemented by AI-assisted development strategies.
According to the findings from Bitdefender, a cybersecurity firm that conducted an extensive investigation into the SilkParasite campaign, seven distinct malware families were identified, of which five were previously unknown to the cybersecurity community. The campaign, which spanned nearly the entirety of 2025, was characterized by a modular and professionally engineered toolset that seamlessly integrated traces of AI-assisted creation. Researchers Marius Baciu, Gheorghe Schipor, and Victor Vrabie noted, “What makes SilkParasite particularly intriguing is the evidence of AI-assisted development within well-crafted code, differing substantially from AI-generated malware.” This distinction underpins the sophistication of the operation, indicating a carefully orchestrated approach to espionage.
This marks the third major cyber operation that Bitdefender has tracked in Central Asia, following earlier initiatives attributed to actors known as UAC-0063 and FamousSparrow. These groups have previously targeted both government entities and critical infrastructure sectors, notably in Europe and Azerbaijan’s oil and gas industries.
As geopolitical dynamics shift, particularly following the conflict in Ukraine, China’s influence in Central Asia is becoming increasingly pronounced, leading to a rise in intelligence-gathering activities. With Russia’s traditional hold on the region waning, Chinese economic engagement has intensified. Researchers assert that this increased economic interaction is accompanied by a parallel need for intelligence operations, further exemplifying the role of cyber warfare in contemporary statecraft.
One of the malware families in the SilkParasite suite notably resembles backdoor components employed by the Chinese-affiliated FamousSparrow group. This indicates a shared toolkit that is characteristic of Chinese espionage techniques. Additionally, the malware primarily utilizes a DLL sideloading technique common among Chinese hackers, ensuring stealthy installation on compromised systems.
The cyber actors behind SilkParasite capitalized on phishing techniques to initially penetrate their targets, using malicious Microsoft Office files delivered via spear-phishing emails. Researchers discovered that several lure documents were packaged within password-protected RAR archives, with the passwords cleverly included in the email body. This approach effectively bypassed standard email gateway defenses and automated security checks, demonstrating a low-cost yet efficient exploitation strategy.
Once the target opened the attachments, a macro embedded within the documents executed, triggering a series of actions that ultimately led to the installation of the initial payload on the victim’s system. Additionally, the attackers showcased an understanding of the antivirus solutions commonly used by their targets, adapting their scripts accordingly to prevent detection. This level of sophistication speaks to the careful planning and resource allocation inherent in state-sponsored cyber operations.
The phishing documents were meticulously crafted to resemble legitimate communication from government ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Some of the lures were even generated using AI, inventing a fictitious energy sector organization and a non-existent cloud-computing provider promoting GPU services. Researchers pointed out that the quality of these AI-generated lures appeared purposely low, with a specific aim to blend in with the subpar content that many target organizations encounter regularly.
Interestingly, the SilkParasite suite distinguished itself from less competent rival operations through the effective use of AI in generating higher-quality malware components, rather than relying solely on volume. This approach contrasts sharply with commodity malware actors who inundate targets with multiple implants. Instead, the APT (Advanced Persistent Threat) groups prioritize stealth and efficiency, executing espionage operations with minimal footprints to avoid detection.
Nearly all seven malware families employed by SilkParasite are characterized by a plug-in structure, allowing for dynamic adaptations and updates without exposing all functionalities to the victims at once. This design choice is a hallmark of APT-grade malware, which aims to limit the risk of exposure while maximizing the operational capabilities of the attackers.
Researchers discovered that two of the identified malware families exhibited telltale signs of AI involvement: GoginRAT, written in Go, retained test functions that would typically be removed before deployment, while NomadRAT, developed in C++, contained hard-coded configuration fields that suggest an AI-assisted workflow. These overlaps indicate a structured design process utilizing AI to refine and optimize malware capabilities, corroborating the presence of engineered ingenuity behind SilkParasite.
In summary, the evolving landscape of cyber threats reveals a continued embrace of sophisticated strategies by state-sponsored actors. The SilkParasite campaign is a testament to the merging of human expertise with AI-enhanced tools, fundamentally redefining the approach to cyber espionage in a rapidly changing geopolitical environment. This convergence of technology and traditional tactics exemplifies the threats that governments may face as they navigate the complex interplay of international relations and cybersecurity.

