Find notable cyber news and cases, enriched with sources, timelines, and signals.

SilkParasite RAT toolkit activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection exposure. The stack combines DLL sideloading, plugin-based modularity, and multiple covert C2 channels to keep operations flexible across victims. One implant uses Google Drive for tasking, while another relies on HTTP Cookie / ETag headers, underscoring a low-footprint design built for stealthy government-targeting espionage.

Related Happenings

SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign

Campaign
H score26 First: 19.08.2026 16:12 Last: 19.08.2026 16:12 Sources 1

How related: A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.

About this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Timeline

  1. 19.08.2026 16:12 2 articles · 3h ago

    SilkParasite RAT toolkit activity

    Initial Disclosure

    SilkParasite emerged as a modular espionage toolkit with multiple RAT families and covert delivery paths. The early cluster already showed DLL sideloading, spear-phishing, and stealth-oriented command-and-control design.

    Show sources