LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
malware

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

zeroday.news ·

A new cyber espionage campaign, designated "SilkParasite," has been identified targeting government entities within Central Asian nations. The operation is notable for its use of seven distinct remote access tool (RAT) families, with five of these tools being previously undocumented. These newly identified RATs have been named DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The SilkParasite campaign was reportedly first detected in late 2025.

The core mechanism of these attacks revolves around the deployment of remote access tools. RATs are a common class of malware designed to provide an attacker with unauthorized, remote control over a compromised system. This control can range from file exfiltration and execution of arbitrary commands to keylogging and surveillance, effectively turning the victim's machine into a persistent foothold for espionage activities. The use of multiple, distinct RAT families suggests a sophisticated adversary potentially employing different tools for varying stages of an attack, different target environments, or to maintain redundancy in their access.

While the specific infection vectors for SilkParasite were not detailed, cyber espionage campaigns commonly leverage spear-phishing emails with malicious attachments or links, exploitation of known vulnerabilities in public-facing applications, or supply chain compromises. Once initial access is gained, the attackers typically establish persistence, escalate privileges, and then deploy their RATs to maintain long-term access and facilitate data exfiltration.

The focus on government bodies in Central Asia indicates a strategic targeting objective, likely aimed at acquiring sensitive political, economic, or military intelligence. This geographic and sectorial targeting is characteristic of state-sponsored or highly organized espionage groups. The discovery of five new RATs suggests a dedicated development effort, indicating a well-resourced and persistent threat actor.

Mitigation strategies for this class of threat generally involve a multi-layered approach. Organizations should prioritize robust email security gateways to filter out malicious attachments and links, implement endpoint detection and response (EDR) solutions to identify and block suspicious activity, and maintain strict patch management policies to address known vulnerabilities promptly. Network segmentation can also limit lateral movement should an intrusion occur.

Furthermore, user awareness training is crucial to educate employees about the dangers of phishing and social engineering. Regular security audits and penetration testing can help identify weaknesses before they are exploited. For government entities, the stakes are particularly high, necessitating advanced threat intelligence capabilities to stay ahead of evolving attack methodologies and custom malware.

The emergence of the SilkParasite campaign, with its array of novel RATs and specific targeting, underscores the ongoing and evolving threat of state-sponsored cyber espionage. It highlights the continuous need for vigilance, advanced defensive measures, and intelligence sharing among targeted sectors and nations to counter sophisticated and persistent adversaries developing custom toolsets to achieve their strategic objectives.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.