A sophisticated espionage campaign, dubbed "SilkParasite," has been uncovered, targeting government entities across Central Asia with previously undocumented malware strains, some of which show signs of AI-assisted development. Cybersecurity firm Bitdefender identified seven distinct malware families in use, five of which had not been previously documented, and linked the operation to state-sponsored actors based in China.
The investigation began with a suspicious infection at an economic-related government institution in an unspecified Central Asian nation. Forensic analysis revealed an operation that had been active for nearly a year, with 65 confirmed infections, predominantly in Asia. The campaign's lure documents were designed to appear relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan, often impersonating official ministries.
Initial access for the attackers was typically gained through spearphishing emails containing malicious Microsoft Office documents. These documents were frequently packaged within archives to bypass email gateway scanning mechanisms.
One of the most widely deployed malware strains, "DriveSilkRAT," exhibited a unique command and control (C2) mechanism. Unlike conventional malware that communicates with dedicated C2 servers, DriveSilkRAT leverages shared Google Drive folders. This method allows the threat actors to blend their malicious traffic with legitimate Google Drive activity, making it less conspicuous to network monitoring tools.
Bitdefender’s attribution of SilkParasite to China is based on several factors, including links between one of the malware strains and another known China-based espionage group, as well as the use of IP addresses tied to Chinese telecommunications companies. The firm theorizes that China's economic expansion in Central Asia, potentially filling a vacuum left by Russia's declining influence, has driven this espionage activity against the region's economic ministries. Bitdefender has also tracked two other China-nexus campaigns in the past year, targeting Europe and South Asia, including recent incidents in the South Caucasus.
A notable aspect of the SilkParasite campaign is the evidence suggesting the use of artificial intelligence in both the creation of lure documents and the development of the malware itself. Bitdefender found that two of the email lures were AI-generated, and placeholders within the malware code indicated AI assistance in its development.
Despite the AI involvement, Bitdefender emphasizes that sophisticated, state-backed malware like that used in SilkParasite remains primarily the work of human professionals. The AI appears to be used as an accelerant, enabling human engineers to work more quickly, rather than fully automating the development process. This approach allows threat actors to leverage AI's speed without introducing the "mediocrity" that could compromise an operation.
This campaign serves as an example of advanced espionage tooling designed for minimal footprint, dynamic in-memory execution, and code deliberately crafted to avoid resemblance to previously identified malware families. The findings highlight the evolving landscape of cyber threats, where even highly capable state-sponsored actors are beginning to integrate AI into their operational workflows.






