A Chinese-nexus cyber-espionage operation is actively targeting government organizations across Central Asia with a collection of mostly previously unidentified remote access Trojans (RATs) from seven different malware families to establish and maintain long-term access to selected victims.
Researchers from Bitdefender Labs began tracking the activity — which they attribute to an advanced persistent threat (APT) group called SilkParasite — in late 2025 after they detected an infection at a Central Asian government body involved in economic decision-making, according to a report published today. The campaign targets government entities across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, using spear-phishing lures tailored to specific ministries and government organizations.
Targets typically receive messages that include regionally tailored Office documents — sometimes inside password-protected RAR archives — which, when opened, trigger a macro that launches a malware delivery chain to deploy a RAT. For some of the archives, attackers include the password in the accompanying email to make the attachments harder for security gateways and automated analysis systems to inspect, according to the report.
Of the seven different types of malware detected, five were previously undocumented and subsequently named by Bitdefender: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The other two RAT families observed in the campaign are the previously documented SpiceRAT and BloodAlchemy.
Overall, "the toolset is small, modular, and professionally engineered, and it carries traces of AI-assisted development," according to Bitdefender. The activity demonstrates key strategic and technical evolutions in both China-linked threat activity and attacker use of AI that have global ramifications.