Illustrative image generated with AI
SilkParasite: AI-Assisted Malware and Economic Espionage in Central Asia
SilkParasite: AI malware targeting Central Asia's economic institutions via spearphishing and Google Drive. Linked to Chinese espionage campaigns.
Text generated by artificial intelligence, published without human review. AI transparency
A Suspicious Infection Reveals a Nearly Year-Long Campaign
On 20 August 2026, Bitdefender published findings from an investigation triggered by a suspicious infection at a government institution responsible for economic affairs in an unspecified Central Asian country. The operation, named SilkParasite, had been active for almost a year at the time of discovery. The exact country has not been disclosed.
The campaign is attributed to a hacker group with military-grade capabilities based in China. The attribution rests on links between at least one malware strain and another known China-based espionage group, as well as several IP addresses used in the campaign that trace back to Chinese telecommunications providers. This is not definitive proof but a convergence of technical and operational indicators.
Initial Access: Office Documents and Spearphishing
The attack begins with spearphishing emails delivering malicious Microsoft Office documents. The lure files are packaged in archives to bypass email gateway filters. This technique circumvents filters that block uncompressed Office attachments.
The lure documents are crafted to appear relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. Several impersonate ministries. The exact Microsoft Office versions involved have not been disclosed. It is unclear whether the campaign exploits specific software vulnerabilities or relies on social engineering to convince victims to enable macros or active content.
Seven Malware Families, Five Unknown, and a C2 on Google Drive
Bitdefender identified seven malware families, five of which had never been documented before. The most widespread strain is DriveSilkRAT, linked to 65 infections, most in Asia. The other six families play a more limited or specialized role.
DriveSilkRAT does not communicate with a dedicated command-and-control server. It uses a shared folder on Google Drive as its C2 channel. The malware reads commands and writes data inside the folder, exploiting traffic to Google Drive, which is less scrutinized than connections to unknown servers. This choice reduces detection by network monitoring systems.
The entire arsenal is designed to limit volume and footprint. Bitdefender describes minimal-footprint techniques, dynamic in-memory execution, and code deliberately built not to resemble earlier malware families. The goal is to remain unnoticed for as long as possible.
Artificial Intelligence Enters Malware Development
The SilkParasite campaign marks a significant shift: two email lures were generated by AI. Additional evidence indicates AI involvement in developing five of the seven malware strains. Placeholders left in the code confirmed the use of AI-assisted coding tools.
According to Bitdefender, AI is used as a development accelerator. The telltale signs are few, and there is no quality degradation in the code. APT-grade malware remains the work of human professionals: AI speeds up writing repetitive modules, generating variants, and producing lures, but does not replace overall design.
Sophisticated state actors are adopting AI-assisted coding selectively, integrating it into professional workflows. This is not full automation but controlled acceleration.
The phenomenon is not isolated. The NSA issued an urgent warning about unnamed actors using AI-generated exploit scripts to target critical industrial technology, with potential dangerous real-world attacks. A week before the NSA warning, Dreamgroup claimed it had observed an automated cyberattack against the government of Taiwan. The use of AI as an offensive tool is becoming a constant.
Targets, Impact, and Geopolitical Context
65 infections have been confirmed, concentrated in Asia. Targets are government institutions related to the economy across six Central Asian countries: Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. The goal is economic espionage.
Bitdefender hypothesizes that the decline of Russian influence in Central Asia created a vacuum filled economically by China. This would explain interest in the economic bodies of regional governments: monitoring policies, agreements, and financial flows in an area increasingly oriented toward Beijing.
The campaign is not an isolated episode. Bitdefender has tracked two other China-linked campaigns over the past year: one aimed at Europe and one at South Asia, including a recent series of incidents against the South Caucasus. SilkParasite is part of broader, persistent activity.
What Organizations Can Do
Bitdefender's report does not include specific mitigations. Detailed indicators of compromise have not been published. Organizations operating in the region or handling sensitive economic data should consider countermeasures based on the described behavior.
Because DriveSilkRAT uses Google Drive as its command-and-control channel, monitoring traffic to this service can help detect anomalous communications from non-browser processes. Strengthening email gateway controls, with attention to compressed archives containing Office documents, reduces initial access risk. Staff training on recognizing spearphishing lures remains a basic measure.
No specific patches are known because no software vulnerabilities have been identified as the primary vector. The attack appears to rely on social engineering and evasion techniques rather than zero-day exploits. However, the lack of detail makes vigilance prudent, especially for government entities and businesses active in Central Asia.
Sources
This article is an original reworking based on the sources below.
