Government networks across Central Asia have been hit by an espionage operation armed with seven remote access tool families, five of them never seen before, according to Bitdefender Labs. The newly documented cluster, named SilkParasite, fields DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT alongside two known RATs.
First observed in late 2025, the group is assessed as China-nexus with medium confidence. What stands out is what Bitdefender calls traces of AI-assisted development running through otherwise expert code, a different thing from AI-generated malware. The arsenal carries the hallmarks of professional tooling built by human operators, with AI used to streamline the process. The clearest sign is a phishing lure that appears indubitably AI-generated, and the only place the adversary seems to have been sloppy, which may be a deliberate attribution trick.
Central Asia is becoming a crowded battlefield: UAC-0063 and FamousSparrow both preceded SilkParasite. Attribution leans Chinese thanks to BLOODALCHEMY, an updated Deed RAT that descends from ShadowPad, itself an evolution of PlugX, tooling long associated with Chinese hacking groups. Elastic Security Labs first documented BLOODALCHEMY in October 2023.
The disclosure gives defenders in the region a concrete tool list to hunt for, and it highlights how quickly AI-assisted workflows are entering state-sponsored espionage.
