Bitdefender specialists discovered a long spy campaign against the state structures of Central Asia, in which the attackers used seven remote management programs. Five of them were not previously described anywhere, and some of the tools were probably created with the help of artificial intelligence.
The campaign was called SilkParasite. According to Bitdefender, the first traces of the operation were found in the fall of 2025 in the network of the state institution related to economic policy. Subsequent analysis showed that the intruders supported the infrastructure for almost a year. The connection of SilkParasite with China is assessed with average confidence and does not yet refer to the operation to a specific group.
To enter the systems, the attackers used malicious documents of Microsoft Office, which were allegedly sent in targeted phishing letters. Some files were placed in password-protected RAR archives, and the password was indicated in the letter itself. The baits were prepared for the organizations of Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan. Another document was intended for the Georgian state structure. The malicious macro also checked the presence of the Kaspersky antivirus and changed behavior if it was detected.
The arsenal of SilkParasite includes DriveSilkRAT, SpiceRAT, CookiETagRAT, BloodAlchemy, NomadRAT, GoginRAT and NodeEdgeRAT. Five of them were not previously known: they are DriveSilkRAT, CookieETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT. Most are built on a modular basis and load additional capabilities only if necessary. Programs written in . NET, C++, Go and JavaScript. To run malicious code, attackers most often swapped DLL libraries next to legitimate signed apps.
The central role is played by DriveSilkRAT. Instead of a separate control server, the program receives commands through the Google Drive shared folder, downloads additional modules from there, and sends the results back. This exchange looks like a normal Google Drive traffic. Experts have found about 65 identifiers of infected systems, mainly in Asia, but warn that the number does not correspond to the exact number of computers.
Other components are masked in their own way. CookieETagRAT hides commands in HTTP headers Cookie and ETag, BloodAlchemy is able to record keystrokes and clipboard contents, and NodeEdgeRAT masks the autorun task under Microsoft Edge update. The full set of technical indicators Bitdefender published in the repository.
In the GoginRAT code, experts found the remaining test functions and the AES key "0123456789abcdef", similar to a temporary plug. The NodeEdgeRAT settings retain the value of “change_this_key”. The similar architecture of NomadRAT and GoginRAT, implemented in different languages, also indicates that they could be developed with the help of AI. Bitdefender evaluates this version with average confidence and emphasizes that the main work was done by qualified developers, and AI probably only accelerated individual tasks.
The campaign was called SilkParasite. According to Bitdefender, the first traces of the operation were found in the fall of 2025 in the network of the state institution related to economic policy. Subsequent analysis showed that the intruders supported the infrastructure for almost a year. The connection of SilkParasite with China is assessed with average confidence and does not yet refer to the operation to a specific group.
To enter the systems, the attackers used malicious documents of Microsoft Office, which were allegedly sent in targeted phishing letters. Some files were placed in password-protected RAR archives, and the password was indicated in the letter itself. The baits were prepared for the organizations of Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan. Another document was intended for the Georgian state structure. The malicious macro also checked the presence of the Kaspersky antivirus and changed behavior if it was detected.
The arsenal of SilkParasite includes DriveSilkRAT, SpiceRAT, CookiETagRAT, BloodAlchemy, NomadRAT, GoginRAT and NodeEdgeRAT. Five of them were not previously known: they are DriveSilkRAT, CookieETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT. Most are built on a modular basis and load additional capabilities only if necessary. Programs written in . NET, C++, Go and JavaScript. To run malicious code, attackers most often swapped DLL libraries next to legitimate signed apps.
The central role is played by DriveSilkRAT. Instead of a separate control server, the program receives commands through the Google Drive shared folder, downloads additional modules from there, and sends the results back. This exchange looks like a normal Google Drive traffic. Experts have found about 65 identifiers of infected systems, mainly in Asia, but warn that the number does not correspond to the exact number of computers.
Other components are masked in their own way. CookieETagRAT hides commands in HTTP headers Cookie and ETag, BloodAlchemy is able to record keystrokes and clipboard contents, and NodeEdgeRAT masks the autorun task under Microsoft Edge update. The full set of technical indicators Bitdefender published in the repository.
In the GoginRAT code, experts found the remaining test functions and the AES key "0123456789abcdef", similar to a temporary plug. The NodeEdgeRAT settings retain the value of “change_this_key”. The similar architecture of NomadRAT and GoginRAT, implemented in different languages, also indicates that they could be developed with the help of AI. Bitdefender evaluates this version with average confidence and emphasizes that the main work was done by qualified developers, and AI probably only accelerated individual tasks.