# SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments

> Bitdefender Labs uncovered SilkParasite, a medium-confidence China-nexus cyberespionage operation targeting economic-policy government bodies across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia. Roughly 65 infections spanned seven modular RAT families (five previously undocumented -- DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT -- plus known SpiceRAT and BloodAlchemy), delivered via DLL side-loading of signed applications and abusing Google Drive as a covert C2 channel.

- **Published:** 2026-08-19T00:00:00Z
- **Last reviewed:** 2026-08-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2200
- **ID:** TL-2026-2200
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** SilkParasite (China)
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

SilkParasite is a roughly year-long cyberespionage campaign that Bitdefender Labs began unraveling in October 2025 after detecting a single suspicious infection at a Central Asian government body responsible for economic decision-making. Follow-on threat hunting surfaced approximately 65 infections across government ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia, all handling economic policy. Initial access was consistently spear-phishing: password-protected RAR archives (to bypass email-gateway scanning) containing malicious Microsoft Office documents with macros tailored to specific ministries, including macros that first check for Kaspersky antivirus before detonating, plus at least two AI-generated lures (a fake energy platform and a GPU cloud-computing advertisement).

The operators deployed seven distinct, professionally engineered RAT families, each with a compact plugin-based architecture that loads capability on demand rather than shipping a monolithic payload. Five were previously undocumented: DriveSilkRAT (.NET/C++, 12 custom plugins, executes processes via WMI to dodge parent-child process monitoring, and receives commands/exfiltrates results through a shared Google Drive folder -- a textbook Living-Off-Trusted-Services technique); CookiETagRAT (C++, hides C2 traffic inside HTTP Cookie and ETag headers, with a per-victim ChaCha20 key derived from the host's system identifier, triggered from DllMain); NomadRAT (C++, orchestrator/transmitter/plugin split, MessagePack serialization wrapped in nested base64 JSON, with a local-fallback plugin mode); GoginRAT (Go, goroutine-based concurrent filesystem/shell sessions supporting multiple simultaneous operators, and containing leftover Go test functions and a hardcoded AES placeholder key -- evidence of AI-assisted development); and NodeEdgeRAT (Node.js, bundles its own Node runtime, single-script with no plugin system, persists via a scheduled task named 'SysEdgeUpdateTaskMachineCore', and calls out to evo.hoster-kg.com, a domain that impersonates the legitimate Kyrgyz ISP hoster.kg). The two known families were SpiceRAT (C/C++, previously documented by Cisco Talos in June 2024 as a tool of the China-linked SneakyChef group, resolving Windows APIs dynamically by hash and persisting via a scheduled task that relaunches every two minutes, hosted on M247 VPS infrastructure) and BloodAlchemy (C/C++, sitting in the ShadowPad/Deed RAT lineage, using HalosGate-style syscall evasion via hardware breakpoints to bypass usermode EDR hooks, with embedded impersonation, clipboard-logging, and keylogging plugins).

All seven families reached the host via passive DLL side-loading of legitimately signed applications: Calibre's ebook-edit.exe loading a malicious calibre-launcher.dll (SpiceRAT, via a HelpLoader sideloading chain), ABBYY FineReader.exe loading dsp_ippv2_x64.dll (BloodAlchemy), Quick Heal's emlproui.exe loading scansts.dll (NomadRAT), Windows Defender's MpDefenderCoreService.exe loading mpclient.dll (DriveSilkRAT's C++ component), Mp3tag.exe loading tak_deco_lib.dll (CookiETagRAT), and an unidentified host loading mscorsvc.dll (GoginRAT). DriveSilkRAT's .NET components were additionally packed with ConfuserEx.

Bitdefender assesses SilkParasite as China-nexus with medium confidence, based on: infrastructure overlap with China Unicom backbone IP ranges; BloodAlchemy's placement in the ShadowPad/Deed RAT (aka SnappyBee) lineage, the same backdoor family Bitdefender separately linked to the China-affiliated FamousSparrow group's multi-wave December 2025-February 2026 intrusion into an Azerbaijani oil and gas firm (via ProxyNotShell exploitation of Microsoft Exchange, a separate initial-access vector from SilkParasite's phishing); and SpiceRAT's prior public attribution by Cisco Talos to SneakyChef, a Chinese-speaking APT that has targeted government ministries across Africa, Asia, and the Middle East (including Kazakhstan and Turkmenistan) with SugarGh0st and SpiceRAT since at least 2023. No single named group has been pinned to the full SilkParasite toolset, and researchers stress the operation remains 'the work of human professionals' who selectively lean on AI tooling (cheap-looking AI-generated phishing lures, AI-assisted code scaffolding in GoginRAT/NodeEdgeRAT) to move faster rather than to replace expert malware engineering. No CVE or software vulnerability is implicated anywhere in the reported kill chain.

## MITRE ATT&CK

- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1047 Windows Management Instrumentation
- T1106 Native API
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1027.002 Obfuscated Files or Information: Software Packing
- T1518.001 Software Discovery: Security Software Discovery
- T1057 Process Discovery
- T1056.001 Input Capture: Keylogging
- T1102.002 Web Service: Bidirectional Communication
- T1071.001 Application Layer Protocol: Web Protocols
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1587.001 Develop Capabilities: Malware
- T1583.006 Acquire Infrastructure: Web Services

## Sources

- [SilkParasite: Tracking a China-Nexus APT Across Central Asia](https://www.bitdefender.com/en-us/blog/businessinsights/silkparasite-tracking-china-nexus-apt-across-central-asia)
- [Malpedia library entry: SilkParasite / BloodAlchemy / ShadowPad / SnappyBee](https://malpedia.caad.fkie.fraunhofer.de/library/a1d0d79a-f394-4f3c-a64c-ce839006e954/)
- [SilkParasite Threatens Central Asian Orgs With Flurry of RATs](https://www.darkreading.com/threat-intelligence/silkparasite-central-asian-orgs-flurry-rats)
- [China's 'SilkParasite' espionage operation targeting Central Asia with AI-assisted malware](https://therecord.media/china-cyber-espionage-central-asia)
- [Unveiling SpiceRAT: SneakyChef's latest tool targeting EMEA and Asia](https://blog.talosintelligence.com/new-spicerat-sneakychef/)
- [FamousSparrow APT Targets Azerbaijani Oil and Gas Industry](https://www.bitdefender.com/en-us/blog/businessinsights/famoussparrow-apt-targets-azerbaijani-oil-gas-industry)
- [Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation](https://thehackernews.com/2026/05/azerbaijani-energy-firm-hit-by-repeated.html)
- [China's AI-Enabled APT Operations Are Getting Interesting](https://www.lawfaremedia.org/article/china's-ai-enabled-apt-operations-are-getting-interesting)
- [China-Nexus SilkParasite APT Deploys Five New RATs Against Central Asian Governments](https://cyberpress.org/silkparasite-targets-central-asia/)
- [bitdefender/malware-ioc: SilkParasite IOC set](https://github.com/bitdefender/malware-ioc)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2200
