By Interestana AI Editorial — AI-drafted, human-overseen. How we report
SilkParasite Espionage Targets Central Asian Governments

A sophisticated cyber espionage operation, identified as SilkParasite, has been actively targeting governmental entities within Central Asia. This previously unreported intrusion set employs a suite of seven distinct remote access tool (RAT) families to achieve its objectives. Notably, five of these RAT families are entirely new to the cybersecurity landscape, having never been documented before their discovery within this campaign. These novel RATs include DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The discovery of SilkParasite was made in late 2025, indicating a sustained period of activity by the threat actor.
Security researchers have assessed that SilkParasite is likely a state-sponsored or state-affiliated actor, given the nature of its targets and the advanced capabilities demonstrated. The campaign's focus on Central Asian governments suggests a strategic interest in the region, potentially for intelligence gathering, political influence, or economic espionage. The use of multiple, custom-developed RATs points to a significant investment in developing bespoke tools, which are often harder to detect and analyze than commercially available or widely distributed malware. This approach allows the attackers to maintain a low profile and evade standard security measures.
The specific functionalities of the newly identified RATs are still under detailed analysis, but their designation as remote access tools implies capabilities such as unauthorized system access, data exfiltration, command and control, and potentially the deployment of further malicious payloads. The ability to deploy five distinct, undocumented RATs within a single campaign highlights the adaptability and resourcefulness of the SilkParasite group. This multi-faceted approach to tool development can also serve to confuse attribution efforts and complicate defensive strategies, as security teams must contend with a wider array of unique attack vectors.
The ongoing investigation into SilkParasite aims to uncover the full scope of its operations, including the specific governments targeted, the duration of the intrusions, and the ultimate goals of the campaign. Understanding the tactics, techniques, and procedures (TTPs) employed by this group is crucial for developing effective countermeasures and bolstering the cybersecurity posture of affected nations. The emergence of such advanced and novel threats underscores the persistent and evolving nature of cyber espionage, particularly in geopolitically sensitive regions like Central Asia. The cybersecurity community continues to monitor for further activity and to share intelligence to mitigate the risks posed by SilkParasite and similar advanced persistent threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.