EXECUTIVE SUMMARY:
SilkParasite is a cyberespionage campaign linked to China-nexus activity that targets government organizations across Central Asia. The campaign focuses on intelligence collection and maintaining persistent access to targeted environments through a stealth-oriented malware ecosystem. The operation has deployed multiple remote access tool (RAT) families, including several previously undocumented variants, demonstrating a mature and professionally maintained capability.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
SilkParasite is a cyberespionage campaign linked to China-nexus activity that targets government organizations across Central Asia. The campaign focuses on intelligence collection and maintaining persistent access to targeted environments through a stealth-oriented malware ecosystem. The operation has deployed multiple remote access tool (RAT) families, including several previously undocumented variants, demonstrating a mature and professionally maintained capability.[emaillocker id="1283"]
The campaign uses spear-phishing emails containing malicious Microsoft Office documents, often delivered through password-protected archives to bypass security scanning mechanisms. After execution, the attackers deploy DLL sideloading techniques by abusing legitimate signed applications to load malicious payloads. The operation involves seven RAT families, including previously undocumented malware such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. These implants use plugin-based architectures, allowing attackers to dynamically load additional capabilities from command-and-control infrastructure. Some malware families leverage trusted services such as Google Drive for command-and-control communication, while others use encrypted communication channels and in-memory execution to evade security monitoring. The campaign also shows signs of AI-assisted development practices within otherwise professionally engineered malware frameworks.
SilkParasite represents a targeted cyber espionage operation focused on maintaining covert access to government networks in Central Asia. The combination of customized RAT families, trusted-service abuse, DLL sideloading, and modular malware design highlights the capability of advanced threat actors to conduct long-term intelligence operations while minimizing detection. Organizations should strengthen phishing defenses, monitor suspicious signed application behavior, detect abnormal cloud service usage, and implement behavioral-based threat monitoring to identify similar activity.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Stealth | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC MAPPING:
| Objective | Behavior ID | Behavior |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Discovery | E1082 | System Information Discovery |
| Execution | E1204 | User Execution |
| Impact | B0022 | Remote Access |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]