Threat reportAPTTL-2026-2200
SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments
SilkParasite (TL-2026-2200) is a high-severity advanced persistent threat campaign, first published 2026-08-19. It is attributed to SilkParasite (China) with medium confidence, affects Calibre Calibre (ebook-edit.exe), maps to 17 MITRE ATT&CK techniques (T1027.002, T1036.005, T1047), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 1SilkParasite
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-2200
- Threat ID
- TL-2026-2200
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- SilkParasite
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, economic-policy, public-sector
- Target regions
- 143 - Central Asia, uzbekistan, turkmenistan, kyrgyzstan, tajikistan, kazakhstan, georgia
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in SilkParasite
Malware and tooling: BloodAlchemy, CookiETagRAT, DriveSilkRAT, GoginRAT, NodeEdgeRAT, NomadRAT, SNAPPYBEE, SpiceRAT, ConfuserEx, ShadowPad
How SilkParasite works
Bitdefender Labs uncovered SilkParasite, a medium-confidence China-nexus cyberespionage operation targeting economic-policy government bodies across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia. Roughly 65 infections spanned seven modular RAT families (five previously undocumented -- DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT -- plus known SpiceRAT and BloodAlchemy), delivered via DLL side-loading of signed applications and abusing Google Drive as a covert C2 channel.
SilkParasite is a roughly year-long cyberespionage campaign that Bitdefender Labs began unraveling in October 2025 after detecting a single suspicious infection at a Central Asian government body responsible for economic decision-making. Follow-on threat hunting surfaced approximately 65 infections across government ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia, all handling economic policy. Initial access was consistently spear-phishing: password-protected RAR archives (to bypass email-gateway scanning) containing malicious Microsoft Office documents with macros tailored to specific ministries, including macros that first check for Kaspersky antivirus before detonating, plus at least two AI-generated lures (a fake energy platform and a GPU cloud-computing advertisement).
The operators deployed seven distinct, professionally engineered RAT families, each with a compact plugin-based architecture that loads capability on demand rather than shipping a monolithic payload. Five were previously undocumented: DriveSilkRAT (.NET/C++, 12 custom plugins, executes processes via WMI to dodge parent-child process monitoring, and receives commands/exfiltrates results through a shared Google Drive folder -- a textbook Living-Off-Trusted-Services technique); CookiETagRAT (C++, hides C2 traffic inside HTTP Cookie and ETag headers, with a per-victim ChaCha20 key derived from the host's system identifier, triggered from DllMain); NomadRAT (C++, orchestrator/transmitter/plugin split, MessagePack serialization wrapped in nested base64 JSON, with a local-fallback plugin mode); GoginRAT (Go, goroutine-based concurrent filesystem/shell sessions supporting multiple simultaneous operators, and containing leftover Go test functions and a hardcoded AES placeholder key -- evidence of AI-assisted development); and NodeEdgeRAT (Node.js, bundles its own Node runtime, single-script with no plugin system, persists via a scheduled task named 'SysEdgeUpdateTaskMachineCore', and calls out to evo.hoster-kg.com, a domain that impersonates the legitimate Kyrgyz ISP hoster.kg). The two known families were SpiceRAT (C/C++, previously documented by Cisco Talos in June 2024 as a tool of the China-linked SneakyChef group, resolving Windows APIs dynamically by hash and persisting via a scheduled task that relaunches every two minutes, hosted on M247 VPS infrastructure) and BloodAlchemy (C/C++, sitting in the ShadowPad/Deed RAT lineage, using HalosGate-style syscall evasion via hardware breakpoints to bypass usermode EDR hooks, with embedded impersonation, clipboard-logging, and keylogging plugins).
All seven families reached the host via passive DLL side-loading of legitimately signed applications: Calibre's ebook-edit.exe loading a malicious calibre-launcher.dll (SpiceRAT, via a HelpLoader sideloading chain), ABBYY FineReader.exe loading dsp_ippv2_x64.dll (BloodAlchemy), Quick Heal's emlproui.exe loading scansts.dll (NomadRAT), Windows Defender's MpDefenderCoreService.exe loading mpclient.dll (DriveSilkRAT's C++ component), Mp3tag.exe loading tak_deco_lib.dll (CookiETagRAT), and an unidentified host loading mscorsvc.dll (GoginRAT). DriveSilkRAT's .NET components were additionally packed with ConfuserEx.
Bitdefender assesses SilkParasite as China-nexus with medium confidence, based on: infrastructure overlap with China Unicom backbone IP ranges; BloodAlchemy's placement in the ShadowPad/Deed RAT (aka SnappyBee) lineage, the same backdoor family Bitdefender separately linked to the China-affiliated FamousSparrow group's multi-wave December 2025-February 2026 intrusion into an Azerbaijani oil and gas firm (via ProxyNotShell exploitation of Microsoft Exchange, a separate initial-access vector from SilkParasite's phishing); and SpiceRAT's prior public attribution by Cisco Talos to SneakyChef, a Chinese-speaking APT that has targeted government ministries across Africa, Asia, and the Middle East (including Kazakhstan and Turkmenistan) with SugarGh0st and SpiceRAT since at least 2023. No single named group has been pinned to the full SilkParasite toolset, and researchers stress the operation remains 'the work of human professionals' who selectively lean on AI tooling (cheap-looking AI-generated phishing lures, AI-assisted code scaffolding in GoginRAT/NodeEdgeRAT) to move faster rather than to replace expert malware engineering. No CVE or software vulnerability is implicated anywhere in the reported kill chain.
MITRE ATT&CK techniques used in TL-2026-2200
Defense Evasion
T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1574.001 DLL
Execution
T1047 Windows Management Instrumentation; T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.002 User Execution: Malicious File
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task
Collection
T1056.001 Input Capture: Keylogging
Discovery
T1057 Process Discovery; T1518.001 Software Discovery: Security Software Discovery
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication
Initial Access
T1566.001 Phishing: Spearphishing Attachment
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Resource Development
T1583.006 Acquire Infrastructure: Web Services; T1587.001 Develop Capabilities: Malware
Affected products and versions in SilkParasite
- Calibre — Calibre (ebook-edit.exe)
Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw, works regardless of Calibre version - ABBYY — FineReader (FineReader.exe)
Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw - Quick Heal — Quick Heal AntiVirus (emlproui.exe)
Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw - Microsoft — Windows Defender (MpDefenderCoreService.exe)
Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw - Mp3tag — Mp3tag (Mp3tag.exe)
Vulnerable versions: signed release binary abused for passive DLL side-loading -- no version-specific flaw
Remediation for SilkParasite
Patches
- No CVE or software vulnerability is involved -- initial access relies on spear-phishing and user-executed malicious Office documents rather than exploitation of a vendor flaw, so no vendor patch applies
Immediate actions
- Hunt for the six documented DLL side-loading pairs (calibre-launcher.dll, dsp_ippv2_x64.dll, scansts.dll, mpclient.dll, tak_deco_lib.dll, mscorsvc.dll) alongside their legitimate host executables (ebook-edit.exe, FineReader.exe, emlproui.exe, MpDefenderCoreService.exe, Mp3tag.exe)
- Alert on outbound traffic to evo.hoster-kg.com and audit Google Drive API/OAuth activity for unexpected shared-folder polling from endpoint processes
- Hunt for the scheduled task 'SysEdgeUpdateTaskMachineCore' and any scheduled task relaunching a non-standard binary every two minutes
- Review endpoints for the persistence path C:\ProgramData\USOShared\Logs\ and the 'fl_bridge' artifact name
Workarounds
- Harden DLL search order / Safe DLL Search Mode on hosts running Calibre, ABBYY FineReader, Quick Heal, Mp3tag, and Windows Defender components to blunt passive side-loading of an attacker-planted DLL from the application directory
Longer-term hardening
- Deploy application allow-listing / DLL search-order hardening (Safe DLL Search Mode) to block unsigned DLLs from loading alongside signed vendor binaries such as Calibre, ABBYY FineReader, Quick Heal, and Mp3tag
- Deploy EDR with kernel-callback or ETW-based telemetry capable of detecting indirect/direct syscall use (HalosGate-style evasion), since usermode API hooking alone is bypassed by this tradecraft
- Restrict or closely monitor egress to consumer cloud-storage APIs (Google Drive and similar) from endpoint fleets that have no legitimate business need for them
- Enforce macro-disabled-by-default policies and inspect password-protected archive attachments at the mail gateway for government email systems in the targeted region
Weaknesses (CWE) in SilkParasite
Timeline of SilkParasite
- Cisco Talos publicly documents SpiceRAT as a tool of the China-linked SneakyChef group targeting EMEA and Asia via DLL sideloading -- one of the two previously known RAT families later folded into the SilkParasite toolset.
- Bitdefender Labs detects a single suspicious infection at a Central Asian government body responsible for economic decision-making, triggering the investigation that uncovers SilkParasite.
- Deed RAT (ShadowPad/SnappyBee lineage, the same family SilkParasite's BloodAlchemy component shares) is deployed against an Azerbaijani oil and gas firm in the first wave of the related FamousSparrow campaign.
- FamousSparrow's third and final intrusion wave against the Azerbaijani energy firm concludes, corroborating continued operational use of the ShadowPad/Deed RAT lineage tied to SilkParasite's BloodAlchemy component.
- Malpedia adds a library entry cross-referencing SilkParasite with BloodAlchemy, ShadowPad, and SnappyBee.
- Bitdefender publishes the SilkParasite indicator set to its public bitdefender/malware-ioc GitHub repository alongside the report.
- Bitdefender Labs publishes 'SilkParasite: Tracking a China-Nexus APT Across Central Asia,' disclosing seven RAT families (five previously undocumented) across roughly 65 infections spanning six Central Asian and Caucasus governments.
- Dark Reading, The Record, and Cyberpress republish and analyze the Bitdefender findings, widening public awareness of the campaign's AI-assisted malware development artifacts.
Sources cited for SilkParasite
- SilkParasite: Tracking a China-Nexus APT Across Central Asia
- Malpedia library entry: SilkParasite / BloodAlchemy / ShadowPad / SnappyBee
- SilkParasite Threatens Central Asian Orgs With Flurry of RATs
- China's 'SilkParasite' espionage operation targeting Central Asia with AI-assisted malware
- Unveiling SpiceRAT: SneakyChef's latest tool targeting EMEA and Asia
- FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
- Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
- China's AI-Enabled APT Operations Are Getting Interesting
- China-Nexus SilkParasite APT Deploys Five New RATs Against Central Asian Governments
- bitdefender/malware-ioc: SilkParasite IOC set
Detection coverage for TL-2026-2200
As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2200 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.