SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
Campaign
Summary
Hide ▲
Show ▼
The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy espionage access. The operation uses multiple RAT families and regionally tailored lures to adapt payloads to victim environments and reduce detection. Researchers assess the cluster as a China-nexus operation first discovered in late 2025.
Related Happenings
SilkParasite RAT toolkit activity
Malware Activity
H score22
First: 19.08.2026 16:12
Last: 19.08.2026 16:12
Sources 1
How related:
The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
About this happening:
SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection expos...
SilkParasite RAT toolkit activity
Malware ActivityHow related: The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
About this happening: SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection expos...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Chinese-speaking threat actor Central Asia government campaign
Campaign
H score29
First: 31.07.2026 21:52
Last: 31.07.2026 21:52
Sources 1
About this happening:
The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...
Chinese-speaking threat actor Central Asia government campaign
CampaignAbout this happening: The Chinese-speaking threat actor is running an active campaign against government organizations in Central Asia and Syria, expanding risk across multiple public-secto...
TA4922 Operation DragonReturn tax-themed phishing campaign
Campaign
H score32
First: 27.07.2026 13:51
Last: 27.07.2026 13:51
Sources 1
About this happening:
A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. Th...
TA4922 Operation DragonReturn tax-themed phishing campaign
CampaignAbout this happening: A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. Th...
Timeline
-
19.08.2026 16:12 2 articles · 3h ago
SilkParasite targets Central Asian government bodies with five new RATs
Initial DisclosureSilkParasite is a China-nexus espionage cluster targeting government bodies in Central Asia with five previously undocumented RAT families, including DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The intrusion set relies on password-protected RAR archives, malicious Microsoft Office documents, macros that trigger DLL sideloading, and regionally tailored lures; Bitdefender also notes checks for Kaspersky antivirus and observed roughly 65 DriveSilkRAT infections, mostly in Asia.
Show sources
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs — thehackernews.com — 19.08.2026 16:12
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs — thehackernews.com — 19.08.2026 16:12