SilkParasite hackers target Central Asian governments with five new RATs and AI-assisted tools

A previously unreported cyber espionage campaign, dubbed SilkParasite, has been discovered targeting government agencies in Central Asia. The operation was first detected in late 2025 by Bitdefender Labs, and researchers assess with medium confidence that the threat cluster is linked to China.
The intrusion set employs seven distinct remote access trojan (RAT) families, five of which are entirely new to the cybersecurity community: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Unlike typical AI-generated malware, SilkParasite's arsenal exhibits all hallmarks of professional espionage tooling developed by human operators. However, traces of AI-assisted development are woven throughout the otherwise expert code, suggesting the group used artificial intelligence to streamline certain aspects of the development process rather than to generate malware outright.
The clearest sign of AI involvement, according to Bitdefender, is a phishing lure that is "indubitably AI-generated." Interestingly, this lure is also the only sloppy element in the entire campaign, raising the possibility that the adversaries deliberately introduced a weak point to confuse attribution efforts.
SilkParasite is the third major threat actor to strike Central Asia in recent years, following UAC-0063 and FamousSparrow. A key link to Chinese cyber operations is the use of a backdoor called BLOODALCHEMY, which is an updated version of Deed RAT. Deed RAT itself is a successor to ShadowPad, which evolved from the well-known PlugX framework. The connection to this lineage of malware families strongly suggests a Chinese nexus, according to the researchers.


