DriveSilkRAT
At a Glance
| Actor / group | SilkParasite (activity cluster; China-nexus assessed at medium confidence) |
| Activity type | Cyberespionage using seven remote access tool (RAT) families |
| Targets / victims | Government bodies across Central Asia, plus one Georgian entity |
| Scale | Roughly 65 infection instances observed, most in Asia; operation ran nearly a year |
| Attribution status | No single named group named; China-nexus link held at medium confidence |
| Source | Bitdefender Labs research report |
TL;DR
Bitdefender Labs uncovered a China-nexus cyberespionage campaign it calls SilkParasite APT. The operators used seven RAT families against Central Asian government targets. Five families were new, and the malware carried traces of AI-assisted development.
What Happened
The SilkParasite APT campaign surfaced from one infection. In October 2025, Bitdefender researchers spotted a single suspicious infection at a Central Asian government body tied to economic decisions. That one alert triggered months of forensic work.
The hunt uncovered seven distinct RAT families. Bitdefender named five of them: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Two others, SpiceRAT and BloodAlchemy, were already known.
Initial access ran through malicious Microsoft Office documents. Spear-phishing email most likely delivered them. In several cases, the operators hid lures inside password-protected RAR archives. They supplied the password in the email body. That trick slips past email-gateway scanning and sandbox inspection.
The lures were tailored to the region. Recovered documents impersonated ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. The delivery macro even checked for Kaspersky’s process before running.
Professional Tooling, Built by an Organization
The toolset points to a team, not a lone coder. Bitdefender wrote that the seven families are “written in four different languages (.NET, C++, Go, and JavaScript), which is itself a tell.” The report added that “this looks like a functioning software organization, not one developer.”
DLL sideloading was the main delivery method. The operators paired a signed program with a malicious library beside it. When the trusted program ran, it loaded the malicious code inside a signed process. They rotated signed hosts across families, so detection tuned to one host missed the rest.
Who Is Behind It
Attribution remains careful. Several signals point toward a China-nexus group. Cisco Talos previously linked SpiceRAT to SneakyChef, a suspected China-based espionage group. Infrastructure analysis found IP addresses tied to China Unicom’s backbone. The victim profile also fits China-nexus intelligence interests.
Even so, Bitdefender did not pin the activity on a single named actor. As the report put it, “Shared tooling ecosystems are not the same as a single controlling actor.” The team designates the cluster as SilkParasite and holds the China-nexus link at medium confidence. Command-activity timestamps suggested an operator time zone of UTC+8.
The AI-Assisted Development Angle
The malware carried tells of AI help. GoginRAT shipped with leftover Go test functions inside the deployed binary. It also used a placeholder AES key set to a plain sequential string. NodeEdgeRAT held a config field set to the literal “change_this_key.”
Bitdefender frames this as assistance, not automation. The report notes that placeholder keys and leftover test code “are exactly the residue an AI-assisted workflow leaves behind.” The company assesses AI-assisted development at medium confidence.
Impact and Scale
DriveSilkRAT is the backbone of the operation. It has the most tracked infections and deployed the other six families. It takes orders through a shared Google Drive folder rather than a dedicated server. That traffic reads as ordinary cloud activity, which many networks trust.
Bitdefender observed roughly 65 infection instances, most in Asia. That figure is an upper bound, since victim identifiers can duplicate. A small count does not mean a small operation. For a targeted actor, a modest victim count is often the point.
What Comes Next and How to Stay Protected
This campaign shows how APTs use AI carefully. They fold it into workflows where it helps and keep it away from places that would expose them. That pattern of China-nexus cyberespionage will likely spread as trusted-cloud C2 grows easier to build.
Defenders should watch trusted cloud services, not just block bad domains. Monitor Google Drive, Slack, and Discord traffic for unusual polling. Flag signed binaries loading DLLs from odd folders. Treat password-protected archives in email as high risk. Hunt for scheduled tasks that mimic Edge or Defender update jobs.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!