LIVE · cybersecurity feed
Live wire
malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

zeroday.news ·

A sophisticated espionage campaign, dubbed "SilkParasite," has been uncovered, targeting government entities across Central Asia with previously undocumented malware strains, some of which show signs of AI-assisted development. Cybersecurity firm Bitdefender identified seven distinct malware families in use, five of which had not been previously documented, and linked the operation to state-sponsored actors based in China.

The investigation began with a suspicious infection at an economic-related government institution in an unspecified Central Asian nation. Forensic analysis revealed an operation that had been active for nearly a year, with 65 confirmed infections, predominantly in Asia. The campaign's lure documents were designed to appear relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan, often impersonating official ministries.

Initial access for the attackers was typically gained through spearphishing emails containing malicious Microsoft Office documents. These documents were frequently packaged within archives to bypass email gateway scanning mechanisms.

One of the most widely deployed malware strains, "DriveSilkRAT," exhibited a unique command and control (C2) mechanism. Unlike conventional malware that communicates with dedicated C2 servers, DriveSilkRAT leverages shared Google Drive folders. This method allows the threat actors to blend their malicious traffic with legitimate Google Drive activity, making it less conspicuous to network monitoring tools.

Bitdefender’s attribution of SilkParasite to China is based on several factors, including links between one of the malware strains and another known China-based espionage group, as well as the use of IP addresses tied to Chinese telecommunications companies. The firm theorizes that China's economic expansion in Central Asia, potentially filling a vacuum left by Russia's declining influence, has driven this espionage activity against the region's economic ministries. Bitdefender has also tracked two other China-nexus campaigns in the past year, targeting Europe and South Asia, including recent incidents in the South Caucasus.

A notable aspect of the SilkParasite campaign is the evidence suggesting the use of artificial intelligence in both the creation of lure documents and the development of the malware itself. Bitdefender found that two of the email lures were AI-generated, and placeholders within the malware code indicated AI assistance in its development.

Despite the AI involvement, Bitdefender emphasizes that sophisticated, state-backed malware like that used in SilkParasite remains primarily the work of human professionals. The AI appears to be used as an accelerant, enabling human engineers to work more quickly, rather than fully automating the development process. This approach allows threat actors to leverage AI's speed without introducing the "mediocrity" that could compromise an operation.

This campaign serves as an example of advanced espionage tooling designed for minimal footprint, dynamic in-memory execution, and code deliberately crafted to avoid resemblance to previously identified malware families. The findings highlight the evolving landscape of cyber threats, where even highly capable state-sponsored actors are beginning to integrate AI into their operational workflows.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.