SilkParasite RAT toolkit activity
Malware Activity
Summary
Hide ▲
Show ▼
SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection exposure. The stack combines DLL sideloading, plugin-based modularity, and multiple covert C2 channels to keep operations flexible across victims. One implant uses Google Drive for tasking, while another relies on HTTP Cookie / ETag headers, underscoring a low-footprint design built for stealthy government-targeting espionage.
Related Happenings
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
Campaign
H score26
First: 19.08.2026 16:12
Last: 19.08.2026 16:12
Sources 1
How related:
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
About this happening:
The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
CampaignHow related: A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
About this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityAbout this happening: The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Timeline
-
19.08.2026 16:12 2 articles · 3h ago
SilkParasite RAT toolkit activity
Initial DisclosureSilkParasite emerged as a modular espionage toolkit with multiple RAT families and covert delivery paths. The early cluster already showed DLL sideloading, spear-phishing, and stealth-oriented command-and-control design.
Show sources
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs — thehackernews.com — 19.08.2026 16:12
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs — thehackernews.com — 19.08.2026 16:12