Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools
New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools
Read Time:3 Minute, 22 Second

Security researchers have uncovered a previously undocumented cyberespionage campaign, dubbed SilkParasite, that has been quietly targeting government institutions across Central Asia. The operation stands out both for the scale of custom tooling behind it and for the care its operators have taken to stay hidden, favoring long-term intelligence collection over noisy, disruptive attacks.

A Toolkit Built for Stealth

Investigators identified seven distinct malware families in use during the campaign, five of which had never been documented publicly before. The newly cataloged tools — tracked under names including DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT — give the attackers a modular arsenal that can be mixed and matched depending on the target environment and the access already achieved.

Rather than relying on a single all-purpose backdoor, the operators appear to deploy different tools at different stages of an intrusion, which both increases resilience against detection and makes it harder for defenders to fingerprint the group based on any one piece of malware.

Getting In: Spear-Phishing With Government-Themed Lures

Initial access relies on classic but effective spear-phishing techniques. Targets receive emails carrying password-protected archives, a tactic specifically designed to slip past automated email security scanners that cannot inspect encrypted attachment contents. Inside the archives are documents themed around government affairs — the kind of official-looking material a targeted civil servant or ministry employee might reasonably expect to receive and open.

Those documents contain malicious macros that, once enabled, kick off the infection chain. The campaign also leans on trusted, legitimate Windows programs to help the malware establish itself quietly, a technique known as DLL sideloading that allows malicious code to load in the context of a signed, trusted process rather than standing out as an obviously foreign executable.

Cloud Infrastructure Instead of Traditional Servers

One of the more notable aspects of SilkParasite is its approach to command-and-control. Instead of relying on conventional dedicated servers, which security teams have become increasingly adept at identifying and blocking through threat intelligence feeds, the operators route command delivery through cloud storage services. This blends malicious traffic in with the enormous volume of legitimate cloud service usage that flows through most corporate and government networks daily, making it substantially harder to spot through network-based detection alone.

Governments Across the Region Targeted

The campaign has been observed targeting government bodies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia. The regional focus, combined with the intelligence-gathering nature of the tooling, points toward a nation-state or state-aligned actor with sustained interest in Central Asian governmental affairs rather than a financially motivated cybercrime group.

Researchers characterized the operation’s overall posture succinctly: the campaign appears designed for intelligence collection rather than widespread disruption. That framing matters for defenders — unlike ransomware or destructive attacks that announce themselves, espionage operations like this one are built to persist undetected for as long as possible while quietly harvesting sensitive information.

Defensive Recommendations

Government agencies and organizations operating in the targeted region — as well as any organization handling sensitive government-adjacent data — should consider the following steps:

  • Treat password-protected archive attachments in unsolicited or unexpected email with heightened scrutiny, since they are specifically used to evade automated scanning
  • Disable macros by default across office document handling policies, enabling them only where explicitly required and verified
  • Monitor for unusual outbound traffic to cloud storage services that doesn’t match normal business usage patterns
  • Apply application allow-listing and monitor for DLL sideloading behavior involving trusted system binaries
  • Maintain updated threat intelligence feeds covering newly identified malware families such as those associated with SilkParasite

An Evolving Threat Picture

The discovery of five previously unknown malware families in a single campaign underscores how much undetected espionage activity likely remains active against government targets worldwide. As threat actors continue to invest in custom tooling and stealthier infrastructure choices like cloud-based command channels, defenders in similarly targeted regions should treat this disclosure as a reminder to revisit email security controls, macro policies, and network monitoring for cloud service abuse.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools, use the discussion on Forum.

>> forum community

Comments

Leave a Reply