Threats

China's SilkParasite Espionage Operation

August 21, 2026 04:00 · 12 min read
China's SilkParasite Espionage Operation

China's 'SilkParasite' espionage operation has been uncovered, targeting government bodies across Central Asia with AI-assisted malware. The operation, allegedly launched by military-grade hackers based in China, has been using five previously undocumented strains of malware to attack government institutions in the region.

Malware and Attack Vectors

Cybersecurity company Bitdefender released a report about the campaign, noting that their investigation began with a suspicious infection at a government institution related to the economy in an unnamed Central Asian country. The company found malicious documents that were made to look relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan, with several impersonating ministries.

The hackers gained initial access through malicious Microsoft Office documents, typically delivered through spearphishing emails. The lure documents were packaged in archives to get around email-gateway scanning. Bitdefender found 65 infections, most of which were in the Asia region, involving DriveSilkRAT, the most widely used of the seven malware strains.

DriveSilkRAT Malware

DriveSilkRAT stood out to Bitdefender because it does not talk to a dedicated command and control server like most malware. Instead, it is linked to a shared Google Drive folder, which the threat actors use because network monitors see it as ordinary Google Drive traffic that is subject to less scrutiny in most corporate environments.

AI Development and Use

One notable aspect of the SilkParasite campaign was the use of artificial intelligence. Bitdefender found that two of the email lures were generated by AI and saw other evidence pointing to the use of AI in the development of the malware strains. The company said the campaign is an example of professional espionage tooling optimized to limit volume, with minimum footprint, dynamic in-memory execution, and code deliberately built not to resemble previous malware families.

The use of AI in the development process was tipped off by several placeholders left in the code of the malware, showing that even sophisticated state-backed actors are conducting AI-assisted coding. Capable threat actors are going to adopt AI slowly and selectively, folding it into professional workflows where it helps and keeping it away from the places where machine-made mediocrity would give the operation away.

Warnings and Implications

After years of warnings, AI's introduction into the cyber threat space appears to be taking form. The National Security Agency released an urgent warning that unnamed threat actors are using AI-generated exploit scripts to target critical industrial technology that would enable dangerous real-world attacks. The warning came one week after another company claimed it saw an automated cyberattack against the government of Taiwan.

The SilkParasite operation has been running for nearly one year, and Bitdefender has tracked two other campaigns with a China nexus targeting Europe and South Asia, including a recent string of incidents aimed at the South Caucasus. The company theorized that Russia's declining influence in Central Asia has opened a vacuum that China has been filling economically, prompting the country to spy on the economic arms of governments in the region.

Bitdefender tied the campaign to China based on links between at least one malware strain and another China-based espionage group. Several of the IP addresses used in the campaign were tied to Chinese telecommunications companies.

The discovery of the SilkParasite operation highlights the growing use of AI in cyber espionage and the need for governments and organizations to be aware of the potential threats and take steps to protect themselves.

As the use of AI in cyber espionage continues to grow, it is essential for organizations to stay vigilant and take proactive measures to protect themselves against these types of threats.


Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free