SilkParasite: malware assistito da IA e spionaggio economico in Asia Centrale
APT

Illustrative image generated with AI

SilkParasite: AI-Assisted Malware and Economic Espionage in Central Asia

SilkParasite: AI malware targeting Central Asia's economic institutions via spearphishing and Google Drive. Linked to Chinese espionage campaigns.

Text generated by artificial intelligence, published without human review. AI transparency

A Suspicious Infection Reveals a Nearly Year-Long Campaign

On 20 August 2026, Bitdefender published findings from an investigation triggered by a suspicious infection at a government institution responsible for economic affairs in an unspecified Central Asian country. The operation, named SilkParasite, had been active for almost a year at the time of discovery. The exact country has not been disclosed.

The campaign is attributed to a hacker group with military-grade capabilities based in China. The attribution rests on links between at least one malware strain and another known China-based espionage group, as well as several IP addresses used in the campaign that trace back to Chinese telecommunications providers. This is not definitive proof but a convergence of technical and operational indicators.

Initial Access: Office Documents and Spearphishing

The attack begins with spearphishing emails delivering malicious Microsoft Office documents. The lure files are packaged in archives to bypass email gateway filters. This technique circumvents filters that block uncompressed Office attachments.

The lure documents are crafted to appear relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. Several impersonate ministries. The exact Microsoft Office versions involved have not been disclosed. It is unclear whether the campaign exploits specific software vulnerabilities or relies on social engineering to convince victims to enable macros or active content.

Seven Malware Families, Five Unknown, and a C2 on Google Drive

Bitdefender identified seven malware families, five of which had never been documented before. The most widespread strain is DriveSilkRAT, linked to 65 infections, most in Asia. The other six families play a more limited or specialized role.

DriveSilkRAT does not communicate with a dedicated command-and-control server. It uses a shared folder on Google Drive as its C2 channel. The malware reads commands and writes data inside the folder, exploiting traffic to Google Drive, which is less scrutinized than connections to unknown servers. This choice reduces detection by network monitoring systems.

The entire arsenal is designed to limit volume and footprint. Bitdefender describes minimal-footprint techniques, dynamic in-memory execution, and code deliberately built not to resemble earlier malware families. The goal is to remain unnoticed for as long as possible.

Artificial Intelligence Enters Malware Development

The SilkParasite campaign marks a significant shift: two email lures were generated by AI. Additional evidence indicates AI involvement in developing five of the seven malware strains. Placeholders left in the code confirmed the use of AI-assisted coding tools.

According to Bitdefender, AI is used as a development accelerator. The telltale signs are few, and there is no quality degradation in the code. APT-grade malware remains the work of human professionals: AI speeds up writing repetitive modules, generating variants, and producing lures, but does not replace overall design.

Sophisticated state actors are adopting AI-assisted coding selectively, integrating it into professional workflows. This is not full automation but controlled acceleration.

The phenomenon is not isolated. The NSA issued an urgent warning about unnamed actors using AI-generated exploit scripts to target critical industrial technology, with potential dangerous real-world attacks. A week before the NSA warning, Dreamgroup claimed it had observed an automated cyberattack against the government of Taiwan. The use of AI as an offensive tool is becoming a constant.

Targets, Impact, and Geopolitical Context

65 infections have been confirmed, concentrated in Asia. Targets are government institutions related to the economy across six Central Asian countries: Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. The goal is economic espionage.

Bitdefender hypothesizes that the decline of Russian influence in Central Asia created a vacuum filled economically by China. This would explain interest in the economic bodies of regional governments: monitoring policies, agreements, and financial flows in an area increasingly oriented toward Beijing.

The campaign is not an isolated episode. Bitdefender has tracked two other China-linked campaigns over the past year: one aimed at Europe and one at South Asia, including a recent series of incidents against the South Caucasus. SilkParasite is part of broader, persistent activity.

What Organizations Can Do

Bitdefender's report does not include specific mitigations. Detailed indicators of compromise have not been published. Organizations operating in the region or handling sensitive economic data should consider countermeasures based on the described behavior.

Because DriveSilkRAT uses Google Drive as its command-and-control channel, monitoring traffic to this service can help detect anomalous communications from non-browser processes. Strengthening email gateway controls, with attention to compressed archives containing Office documents, reduces initial access risk. Staff training on recognizing spearphishing lures remains a basic measure.

No specific patches are known because no software vulnerabilities have been identified as the primary vector. The attack appears to rely on social engineering and evasion techniques rather than zero-day exploits. However, the lack of detail makes vigilance prudent, especially for government entities and businesses active in Central Asia.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsSilkParasiteAI malwareCentral Asiaeconomic espionagespearphishingGoogle DriveChinese hackers
Back to home