Threat Advisory

SilkParasite Campaign Deploys DLL Sideloading and Legitimate Applications to Secure Remote Control

Threat: Malware Campaign
Targeted Region: Central Asia
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

SilkParasite is a cyberespionage campaign linked to China-nexus activity that targets government organizations across Central Asia. The campaign focuses on intelligence collection and maintaining persistent access to targeted environments through a stealth-oriented malware ecosystem. The operation has deployed multiple remote access tool (RAT) families, including several previously undocumented variants, demonstrating a mature and professionally maintained capability.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

SilkParasite is a cyberespionage campaign linked to China-nexus activity that targets government organizations across Central Asia. The campaign focuses on intelligence collection and maintaining persistent access to targeted environments through a stealth-oriented malware ecosystem. The operation has deployed multiple remote access tool (RAT) families, including several previously undocumented variants, demonstrating a mature and professionally maintained capability.[emaillocker id="1283"]

The campaign uses spear-phishing emails containing malicious Microsoft Office documents, often delivered through password-protected archives to bypass security scanning mechanisms. After execution, the attackers deploy DLL sideloading techniques by abusing legitimate signed applications to load malicious payloads. The operation involves seven RAT families, including previously undocumented malware such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. These implants use plugin-based architectures, allowing attackers to dynamically load additional capabilities from command-and-control infrastructure. Some malware families leverage trusted services such as Google Drive for command-and-control communication, while others use encrypted communication channels and in-memory execution to evade security monitoring. The campaign also shows signs of AI-assisted development practices within otherwise professionally engineered malware frameworks.

SilkParasite represents a targeted cyber espionage operation focused on maintaining covert access to government networks in Central Asia. The combination of customized RAT families, trusted-service abuse, DLL sideloading, and modular malware design highlights the capability of advanced threat actors to conduct long-term intelligence operations while minimizing detection. Organizations should strengthen phishing defenses, monitor suspicious signed application behavior, detect abnormal cloud service usage, and implement behavioral-based threat monitoring to identify similar activity.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.006 Command and Scripting Interpreter Python
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Stealth T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC MAPPING:

Objective Behavior ID Behavior
Anti-Static Analysis B0032 Executable Code Obfuscation
Discovery E1082 System Information Discovery
Execution E1204 User Execution
Impact B0022 Remote Access

 

REFERENCES:

The following reports contain further technical details:

https://www.bitdefender.com/en-us/blog/businessinsights/silkparasite-tracking-china-nexus-apt-across-central-asia

[/emaillocker]
crossmenu