Threat reportAPTTL-2026-2200

SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments

highACTIVE

SilkParasite (TL-2026-2200) is a high-severity advanced persistent threat campaign, first published 2026-08-19. It is attributed to SilkParasite (China) with medium confidence, affects Calibre Calibre (ebook-edit.exe), maps to 17 MITRE ATT&CK techniques (T1027.002, T1036.005, T1047), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
1SilkParasite
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-2200

Threat ID
TL-2026-2200
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
SilkParasite
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, economic-policy, public-sector
Target regions
143 - Central Asia, uzbekistan, turkmenistan, kyrgyzstan, tajikistan, kazakhstan, georgia
Detection rules
9
Indicators of compromise
21

Malware and tooling in SilkParasite

Malware and tooling: BloodAlchemy, CookiETagRAT, DriveSilkRAT, GoginRAT, NodeEdgeRAT, NomadRAT, SNAPPYBEE, SpiceRAT, ConfuserEx, ShadowPad

How SilkParasite works

Bitdefender Labs uncovered SilkParasite, a medium-confidence China-nexus cyberespionage operation targeting economic-policy government bodies across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia. Roughly 65 infections spanned seven modular RAT families (five previously undocumented -- DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT -- plus known SpiceRAT and BloodAlchemy), delivered via DLL side-loading of signed applications and abusing Google Drive as a covert C2 channel.

SilkParasite is a roughly year-long cyberespionage campaign that Bitdefender Labs began unraveling in October 2025 after detecting a single suspicious infection at a Central Asian government body responsible for economic decision-making. Follow-on threat hunting surfaced approximately 65 infections across government ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia, all handling economic policy. Initial access was consistently spear-phishing: password-protected RAR archives (to bypass email-gateway scanning) containing malicious Microsoft Office documents with macros tailored to specific ministries, including macros that first check for Kaspersky antivirus before detonating, plus at least two AI-generated lures (a fake energy platform and a GPU cloud-computing advertisement).

The operators deployed seven distinct, professionally engineered RAT families, each with a compact plugin-based architecture that loads capability on demand rather than shipping a monolithic payload. Five were previously undocumented: DriveSilkRAT (.NET/C++, 12 custom plugins, executes processes via WMI to dodge parent-child process monitoring, and receives commands/exfiltrates results through a shared Google Drive folder -- a textbook Living-Off-Trusted-Services technique); CookiETagRAT (C++, hides C2 traffic inside HTTP Cookie and ETag headers, with a per-victim ChaCha20 key derived from the host's system identifier, triggered from DllMain); NomadRAT (C++, orchestrator/transmitter/plugin split, MessagePack serialization wrapped in nested base64 JSON, with a local-fallback plugin mode); GoginRAT (Go, goroutine-based concurrent filesystem/shell sessions supporting multiple simultaneous operators, and containing leftover Go test functions and a hardcoded AES placeholder key -- evidence of AI-assisted development); and NodeEdgeRAT (Node.js, bundles its own Node runtime, single-script with no plugin system, persists via a scheduled task named 'SysEdgeUpdateTaskMachineCore', and calls out to evo.hoster-kg.com, a domain that impersonates the legitimate Kyrgyz ISP hoster.kg). The two known families were SpiceRAT (C/C++, previously documented by Cisco Talos in June 2024 as a tool of the China-linked SneakyChef group, resolving Windows APIs dynamically by hash and persisting via a scheduled task that relaunches every two minutes, hosted on M247 VPS infrastructure) and BloodAlchemy (C/C++, sitting in the ShadowPad/Deed RAT lineage, using HalosGate-style syscall evasion via hardware breakpoints to bypass usermode EDR hooks, with embedded impersonation, clipboard-logging, and keylogging plugins).

All seven families reached the host via passive DLL side-loading of legitimately signed applications: Calibre's ebook-edit.exe loading a malicious calibre-launcher.dll (SpiceRAT, via a HelpLoader sideloading chain), ABBYY FineReader.exe loading dsp_ippv2_x64.dll (BloodAlchemy), Quick Heal's emlproui.exe loading scansts.dll (NomadRAT), Windows Defender's MpDefenderCoreService.exe loading mpclient.dll (DriveSilkRAT's C++ component), Mp3tag.exe loading tak_deco_lib.dll (CookiETagRAT), and an unidentified host loading mscorsvc.dll (GoginRAT). DriveSilkRAT's .NET components were additionally packed with ConfuserEx.

Bitdefender assesses SilkParasite as China-nexus with medium confidence, based on: infrastructure overlap with China Unicom backbone IP ranges; BloodAlchemy's placement in the ShadowPad/Deed RAT (aka SnappyBee) lineage, the same backdoor family Bitdefender separately linked to the China-affiliated FamousSparrow group's multi-wave December 2025-February 2026 intrusion into an Azerbaijani oil and gas firm (via ProxyNotShell exploitation of Microsoft Exchange, a separate initial-access vector from SilkParasite's phishing); and SpiceRAT's prior public attribution by Cisco Talos to SneakyChef, a Chinese-speaking APT that has targeted government ministries across Africa, Asia, and the Middle East (including Kazakhstan and Turkmenistan) with SugarGh0st and SpiceRAT since at least 2023. No single named group has been pinned to the full SilkParasite toolset, and researchers stress the operation remains 'the work of human professionals' who selectively lean on AI tooling (cheap-looking AI-generated phishing lures, AI-assisted code scaffolding in GoginRAT/NodeEdgeRAT) to move faster rather than to replace expert malware engineering. No CVE or software vulnerability is implicated anywhere in the reported kill chain.

MITRE ATT&CK techniques used in TL-2026-2200

Defense Evasion

T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1574.001 DLL

Execution

T1047 Windows Management Instrumentation; T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.002 User Execution: Malicious File

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task

Collection

T1056.001 Input Capture: Keylogging

Discovery

T1057 Process Discovery; T1518.001 Software Discovery: Security Software Discovery

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication

Initial Access

T1566.001 Phishing: Spearphishing Attachment

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1587.001 Develop Capabilities: Malware

Affected products and versions in SilkParasite

  • Calibre — Calibre (ebook-edit.exe)
    Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw, works regardless of Calibre version
  • ABBYY — FineReader (FineReader.exe)
    Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw
  • Quick Heal — Quick Heal AntiVirus (emlproui.exe)
    Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw
  • Microsoft — Windows Defender (MpDefenderCoreService.exe)
    Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw
  • Mp3tag — Mp3tag (Mp3tag.exe)
    Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw

Remediation for SilkParasite

Patches

  • No CVE or software vulnerability is involved -- initial access relies on spear-phishing and user-executed malicious Office documents rather than exploitation of a vendor flaw, so no vendor patch applies

Immediate actions

  • Hunt for the six documented DLL side-loading pairs (calibre-launcher.dll, dsp_ippv2_x64.dll, scansts.dll, mpclient.dll, tak_deco_lib.dll, mscorsvc.dll) alongside their legitimate host executables (ebook-edit.exe, FineReader.exe, emlproui.exe, MpDefenderCoreService.exe, Mp3tag.exe)
  • Alert on outbound traffic to evo.hoster-kg.com and audit Google Drive API/OAuth activity for unexpected shared-folder polling from endpoint processes
  • Hunt for the scheduled task 'SysEdgeUpdateTaskMachineCore' and any scheduled task relaunching a non-standard binary every two minutes
  • Review endpoints for the persistence path C:\ProgramData\USOShared\Logs\ and the 'fl_bridge' artifact name

Workarounds

  • Harden DLL search order / Safe DLL Search Mode on hosts running Calibre, ABBYY FineReader, Quick Heal, Mp3tag, and Windows Defender components to blunt passive side-loading of an attacker-planted DLL from the application directory

Longer-term hardening

  • Deploy application allow-listing / DLL search-order hardening (Safe DLL Search Mode) to block unsigned DLLs from loading alongside signed vendor binaries such as Calibre, ABBYY FineReader, Quick Heal, and Mp3tag
  • Deploy EDR with kernel-callback or ETW-based telemetry capable of detecting indirect/direct syscall use (HalosGate-style evasion), since usermode API hooking alone is bypassed by this tradecraft
  • Restrict or closely monitor egress to consumer cloud-storage APIs (Google Drive and similar) from endpoint fleets that have no legitimate business need for them
  • Enforce macro-disabled-by-default policies and inspect password-protected archive attachments at the mail gateway for government email systems in the targeted region

Weaknesses (CWE) in SilkParasite

CWE-427, CWE-506

Timeline of SilkParasite

  • Cisco Talos publicly documents SpiceRAT as a tool of the China-linked SneakyChef group targeting EMEA and Asia via DLL sideloading -- one of the two previously known RAT families later folded into the SilkParasite toolset.
  • Bitdefender Labs detects a single suspicious infection at a Central Asian government body responsible for economic decision-making, triggering the investigation that uncovers SilkParasite.
  • Deed RAT (ShadowPad/SnappyBee lineage, the same family SilkParasite's BloodAlchemy component shares) is deployed against an Azerbaijani oil and gas firm in the first wave of the related FamousSparrow campaign.
  • FamousSparrow's third and final intrusion wave against the Azerbaijani energy firm concludes, corroborating continued operational use of the ShadowPad/Deed RAT lineage tied to SilkParasite's BloodAlchemy component.
  • Malpedia adds a library entry cross-referencing SilkParasite with BloodAlchemy, ShadowPad, and SnappyBee.
  • Bitdefender publishes the SilkParasite indicator set to its public bitdefender/malware-ioc GitHub repository alongside the report.
  • Bitdefender Labs publishes 'SilkParasite: Tracking a China-Nexus APT Across Central Asia,' disclosing seven RAT families (five previously undocumented) across roughly 65 infections spanning six Central Asian and Caucasus governments.
  • Dark Reading, The Record, and Cyberpress republish and analyze the Bitdefender findings, widening public awareness of the campaign's AI-assisted malware development artifacts.

Sources cited for SilkParasite

Detection coverage for TL-2026-2200

As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2200 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats