Researchers say a China-linked espionage operation targeted government bodies in Central Asia with spearphishing emails and at least five previously undocumented malware strains. Bitdefender traced the year-long campaign, dubbed SilkParasite, to malicious Microsoft Office documents sent in archive files to evade email scanning, with 65 known infections and lures impersonating ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. One malware family, DriveSilkRAT, used shared Google Drive folders for command-and-control traffic to blend in with normal cloud activity.
Why it matters: This is a live state-linked spying campaign against government institutions, especially economic agencies, and it shows attackers mixing custom malware with AI-assisted development to move faster and hide better. Government defenders and organizations in the region should hunt for the named malware families, review phishing defenses, and scrutinize unusual Google Drive traffic and archive-based Office lures.
2026.08.20
100% relevant
This article appears to be the first cited report establishing the SilkParasite campaign as a distinct China-linked espionage operation with named malware, targeting pattern, and AI-assisted development details.
← Back to all stories