SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia — Threadlinqs Intelligence
As of 2026-08-19, SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia is a high-severity apt threat attributed to SilkParasite (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-2068 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: SilkParasite · China · ESPIONAGE
Bitdefender tracks SilkParasite, a China-nexus cyberespionage campaign (medium confidence) targeting Central Asian government bodies involved in economic decision-making. Active since at least early
Bitdefender Labs researchers Marius Baciu, Gheorghe Schipor, and Victor Vrabie published the SilkParasite campaign analysis on August 19, 2026, documenting a China-nexus espionage operation (medium confidence) targeting government bodies across five Central Asian states — Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan — plus Georgia. The operation was discovered following a single infection at a Central Asian government body around October 2025, triggering months of forensic investigation and threat hunting that revealed the campaign had been running for roughly the better part of a year (since approximately early 2025).
SilkParasite is distinguished by its deployment of seven distinct malware families across four programming languages (C/C++, Go, JavaScript/Node.js, and .NET/C#), forming one of the most diverse tool arsenals observed in a single espionage campaign. Families range from sophisticated, multi-plugin RATs like DriveSilkRAT (Google Drive-based C2) and BloodAlchemy (ShadowPad/Deed RAT lineage with HalosGate syscall evasion) to specialized implants like CookiETagRAT (command delivery via HTTP Cookie and ETag headers with per-host ChaCha20 encryption) and GoginRAT (Go-based with dual-goroutine independent shells). The malware is delivered through spear-phishing emails containing password-protected RAR archives (password supplied in email body to bypass gateway sandboxes), with malicious Office documents executing macros that deploy a DLL sideloading chain using legitimate signed applications.
DLL sideloading is the campaign's primary execution mechanism, with six confirmed signed-legitimate-application pairs: Calibre's ebook-edit.exe loading calibre-launcher.dll (tracked as HelpLoader), ABBYY FineReader.exe loading dsp_ippv2_x64.dll (BloodAlchemy), Quick Heal's emlproui.exe loading scansts.dll (NomadRAT), Windows Defender's MpDefenderCoreService.exe loading mpclient.dll (DriveSilkRAT C++ variant), Mp3tag.exe loading tak_deco_lib.dll (CookiETagRAT), and an unknown .NET utility (likely mscorsvw.exe) loading mscorsvc.dll (GoginRAT). Each sideloading host is a legitimate signed application, making detection based on hash or signature alone ineffective.
Command and control demonstrates deliberate diversity and a preference for blending into trusted services. DriveSilkRAT uses Google Drive shared folders (Living Off Trusted Services/LOTS) — operators drop command files, the host polls, fetches in-memory .NET plugins, and uploads results. CookiETagRAT embeds C2 commands in HTTP Cookie and ETag headers with per-host ChaCha20 encryption keyed to a system identifier plus fixed suffix, so traffic from one victim cannot decrypt another's. BloodAlchemy operates across TCP, HTTP/S, DNS, and SMB. Operators were active in UTC+8 timezone (derived from 37 Google Drive command timestamps).
Attribution rests on medium-confidence evidence: tooling lineage linking SpiceRAT to Cisco Talos's SneakyChef (China-nexus cluster); BloodAlchemy's shared data structures with Deed RAT (ShadowPad lineage, the latter being FamousSparrow's primary backdoor, which Bitdefender tied to an Azerbaijani oil/gas campaign in May 2026); several C2 IPs traced to China Unicom's backbone; and victimology consistent with Chinese strategic intelligence priorities in Central Asia. Bitdefender does not pin the activity to a single named group, instead designating it as the SilkParasite activity cluster — reflecting the observation that tooling, techniques, and infrastructure circulate across otherwise distinct China-nexus groups.
Geopolitically, SilkParasite forms the third data point in a Bitdefender-observed arc: UAC-0063/TAG-110 (February 2025, targeting Central Asian and European diplomatic/government bodies), FamousSparrow (May 2026, targeting Azerbaijani oil and gas), and now SilkParasite (August 2026, Central Asian economic-policy government bodies). Bitdefender contextualizes this with Russia's declining influence in Central Asia since th
Target sectors: government administration, economic-policy, energy
Target regions: 143 - Central Asia, South Caucasus
Timeline
- SneakyChef activity cluster (SpiceRAT operator, linked to SilkParasite tooling) first observed active by Cisco Talos and other researchers
- ITOCNU publishes public analysis of BloodAlchemy loader — later confirmed as part of ShadowPad/Deed RAT lineage shared by SilkParasite
- Cisco Talos publishes SpiceRAT/SneakyChef report documenting China-nexus espionage targeting 9+ countries with SpiceRAT and SugarGh0st malware
- SilkParasite operation estimated to have begun based on forensic evidence showing approximately one year of activity prior to discovery in late 2025
- Bitdefender publishes UAC-0063/TAG-110 investigation — Russia-linked espionage targeting Central Asian diplomatic and government bodies, the first data point in the observed arc of cyber operations in the region
- Bitdefender Labs detects first SilkParasite infection at a Central Asian government body involved in economic decision-making, triggering months of forensic investigation and threat hunting
- Bitdefender publishes FamousSparrow investigation detailing multi-wave intrusion against Azerbaijani oil and gas company using Deed RAT (shared ShadowPad lineage with SilkParasite's BloodAlchemy)
- Bitdefender completes forensic analysis of 7 malware families, ~65 infection instances, and 37 operator-issued commands — operator activity timezone derived as UTC+8 from Google Drive timestamps
- Bitdefender Labs publishes comprehensive SilkParasite report publicly disclosing the campaign, 7 malware families (5 newly identified), and full IOC set via GitHub repository
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1059, T1047, T1203, T1053, T1574, T1027, T1685, T1055