SilkParasite Fields Five New RATs in Central Asia

Bitdefender Labs documented SilkParasite, a previously unreported China-nexus espionage cluster targeting government bodies in Central Asia with seven remote access tool (RAT) families, five of them newly documented. The set includes DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The group delivers password-protected RAR archives with malicious Office documents, then uses a macro to trigger DLL sideloading, where a legitimate program loads the malware for it. That lets the code run under a trusted binary and makes single-sample detection less dependable, especially when the actor can swap among multiple implants. Bitdefender says the code shows signs of likely AI-assisted development, but the operation still appears human-directed and professionally built. For government networks in Central Asia, the lasting issue is not one named RAT but a tooling set that can change shape while the campaign stays on target.

Part of the PlainSec briefing for 2026-08-19

Editions

Sources