A previously undocumented espionage group called SilkParasite has been targeting government organizations across Central Asia, according to cybersecurity researchers at Bitdefender.
The group, first identified in late 2025, is believed with medium confidence to have links to China. Its attacks use seven remote access tools, including five malware families that had not been publicly documented before: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT.
Researchers said the malware appears to have been created mainly by human operators, but shows signs of AI-assisted development. One phishing document used in the attacks appears to have been created with AI. Bitdefender said this may have been deliberate to make the attackers harder to identify.
The campaign has targeted government organizations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan. Some malicious documents were designed to look like official government documents and impersonated specific ministries.
The attacks involved password-protected RAR files containing malicious Microsoft Office documents. When opened, the documents use macros to install malware using the DLL sideloading technique.
The campaign also uses tools linked to Chinese-speaking threat actors, including BLOODALCHEMY and an updated version of SpiceRAT.
Most of the malware uses a modular design, allowing the attackers to add or change features without replacing the main module. Researchers said this helps the group adapt its attacks and reduce the chances of detection.
Bitdefender also found that the malware checks whether Kaspersky antivirus is running before continuing. This suggests the threat actors are taking steps to avoid security software commonly used in the region.