← All Incident Reports
Incident report · TESSOC: Espionage / Cyber
Sustained collection against neighbouring states

SilkParasite: government networks in five Central Asian states and Georgia

Bitdefender has published a campaign it calls SilkParasite, running against government bodies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan and Georgia since late 2025 and still active this month.

Seven families of remote access software, five of them newly named. Two details are worth more than the tool count: the lure documents impersonated specific ministries in each country, and the macro checks whether Kaspersky is running before it acts, and adapts its behaviour accordingly.

↓  Download one-page brief (PDF)
Who
Actor: a previously unreported cluster Bitdefender Labs tracks as SilkParasite and assesses, at medium confidence, to be China-nexus. That assessment is a single vendor's and is uncorroborated at time of writing. Victims: government bodies across Central Asia and the South Caucasus. Casualties: not applicable.
What
A sustained cyber-espionage campaign built on seven remote access trojan families, of which five were previously undocumented and have been named by the researchers as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT. The toolset is described as small, modular and professionally engineered, and Bitdefender observed roughly 65 machines carrying the principal tool.
Where
Government targets in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan and Georgia.
When
Activity dated from late 2025 to at least August 2026, publicly disclosed on 19 August 2026.
Why
Consistent with state-level intelligence collection against the governments concerned. Both the region and the target set fit a collection priority, but no motive has been established and the state connection is an assessment rather than a finding.
How
Spear-phishing delivering password-protected archives containing malicious Office documents; the macros trigger a loading sequence that side-loads the remote access tools. The macro first checks whether Kaspersky antivirus is present on the machine.
What happened
Uzbekistan Turkmenistan Kyrgyzstan Tajikistan Kazakhstan Georgia SILKPARASITE: GOVERNMENT TARGETS Five Central Asian states and Georgia 500 km N Schematic. Boundaries and transport: Natural Earth 1:10m, public domain.
1

A password-protected archive arrives

The initial approach is spear-phishing carrying a RAR archive with a password. The password is the point: an encrypted archive cannot be inspected by a mail gateway or scanned on arrival, so the file reaches the desktop intact and the recipient supplies the key.

2

The lure is written for the ministry it is sent to

The recovered documents were tailored to each country, several impersonating specific ministries, with a further document addressed to a Georgian government entity recovered from a public malware-sharing platform rather than from a victim. That is targeting research done before the first email is sent.

3

The macro checks the room before it acts

Before executing, the macro establishes whether Kaspersky's process is running on the machine and adapts its behaviour accordingly - not merely aborting, but changing what it does. Kaspersky is widely deployed across the region, so this is a defensive-estate adaptation rather than generic evasion.

4

The tools are side-loaded rather than installed

The macro triggers a sequence that loads the remote access software through a legitimate program rather than by installing something recognisable of its own. What runs on the machine then provides process listing, file handling, command execution and the ability to load further modules.

5

Seven families, five of them new

The campaign uses seven distinct tool families, of which five had not been documented before and two were already known. That breadth is unusual and it multiplies the work required of any defender trying to detect the activity by signature.

6

Roughly sixty-five machines, and a disclosure

Bitdefender observed about 65 machines carrying the principal tool and published on 19 August. The count is what the vendor could see, not necessarily the extent of the campaign.

Impact
Confidentiality
Compromise of government networks across six states, with persistent remote access and the ability to enumerate, retrieve and execute at will. The loss is of confidentiality over whatever those networks hold, which is unquantified.
Detection cost
Five new tool families in one disclosure is the practical burden. Every defender in the region now has five sets of indicators to deploy and no history of them, and signature-based detection was of no use during the period the campaign was running.
Sovereignty
Six governments with limited independent capability carrying persistent access by an external actor. The effect is on their ability to hold their own information, which is a question of sovereignty rather than of any individual document.
Regional
Central Asia and the South Caucasus sit between Russia, China and the Caspian energy routes, with infrastructure investment from several directions. Collection against these governments is valuable to more than one party, which is worth holding alongside a medium-confidence attribution.
The region, the method and the caveat
The region

Between three interests at once

The five Central Asian republics and Georgia sit on energy routes and infrastructure corridors of interest to China, to Russia and to Europe. Governments there hold negotiating positions, contract terms and internal assessments that several external parties would find useful.

The archive

Why a password defeats the gateway

Mail security inspects attachments. An encrypted archive cannot be inspected, and supplying the password in the message body transfers the decryption to the recipient, past the control. It is an old technique and it continues to work.

The check

Antivirus as a targeting signal

A macro that looks for one specific product before acting tells you the operator has a view of the estate. Kaspersky is widely deployed across the former Soviet space, so checking for it is a regional adaptation rather than a generic evasion.

The basis

What the attribution actually rests on

Bitdefender cites a technical overlap - one SilkParasite tool resembling a backdoor used by the China-aligned FamousSparrow - together with DLL side-loading as a delivery method common among Chinese actors, and a strategic rationale: as Russian influence in Central Asia and the South Caucasus has receded since the war in Ukraine, Chinese economic engagement has increased and collection follows commerce. That is a reasoned case rather than an assertion, and it is still one company's assessment at medium confidence.

Two things should be held apart here. That the campaign exists and compromised government machines is vendor-documented and specific. That it is Chinese is one company's medium-confidence judgement, and a reader who carries the first forward as established and the second as equally solid will have imported an attribution nobody has stood behind.

Assessment
1

The antivirus check is the most revealing detail in the disclosure

A macro that establishes whether one particular product is present before executing indicates an operator who has studied the defensive estate of the region it is working in, and who has decided how to behave when that product is found. That is target-aware tradecraft rather than commodity malware, and it is more informative about the actor's maturity than the number of tool families.

2

Password-protected archives remain effective because the control cannot see inside them

Encrypting an attachment and supplying the password in the covering message defeats gateway inspection by design, and the recipient completes the attack by decrypting it. It is not a sophisticated technique. Where an organisation permits encrypted archives to arrive by mail, it has accepted that a class of attachment will not be inspected, and that is a policy decision more than a technical one.

3

The AI finding is narrower than the headlines around it, and more interesting

Bitdefender describes traces of AI-assisted development running through otherwise expert code, and is explicit that this is a different thing from AI-generated malware: the toolset has the hallmarks of professional tooling built by human operators, with AI apparently used to streamline the work rather than to produce it. The distinction matters because the two produce opposite signatures - generated malware tends to be voluminous and undisciplined, while this is small, modular and deliberately built not to resemble earlier families. The clearest AI artefact the researchers point to is a phishing lure, not the malware.

4

Five new families in one disclosure is a statement about resourcing

Maintaining seven tool families, five of them unknown until this month, requires sustained development rather than a purchased kit, and Bitdefender records this as the third operation it has observed against this region after UAC-0063 and FamousSparrow. It is a realistic possibility that this reflects a state-resourced programme.

5

The attribution has a stated basis, and it is still one vendor at medium confidence

The reasoning is set out rather than asserted: a tool resembling a FamousSparrow backdoor, side-loading consistent with Chinese tradecraft, and a regional context in which Chinese engagement has grown as Russian influence has receded. No government has attributed the activity and no second researcher has corroborated it. The disciplined entry records a documented intrusion set against six named governments with a reasoned but uncorroborated attribution attached, and does not firm that attribution up by repeating it.

6

Collection against these governments will continue

The region's position between larger interests, its infrastructure exposure and the modest defensive capability of several of the states concerned make it a durable target. It is highly likely that spear-phishing with weaponised Office documents remains the principal route into government networks across the region, because it continues to work.

The comparison worth making

Set this beside Jewelbug, disclosed five days earlier and also assessed as China-nexus. Bitdefender is explicit that these are separate campaigns with separate toolsets. The temptation to merge two vendor disclosures about one country into a single picture is exactly what an analyst should resist, because the result is a composite adversary that does not exist.

What should carry
  • Decide your policy on encrypted archives arriving by mail. If a password-protected attachment cannot be inspected, permitting it is a decision to let an uninspected file class through. Blocking it, quarantining it or requiring detonation are all defensible; doing nothing is not.
  • Assume an adversary knows which security products you run. This macro checked for one specific vendor. Procurement is often public, particularly in the government sector, and it should be assumed to be known.
  • Do not rely on signatures for a campaign that is still being documented. Five of these seven families were unknown until this month. Behavioural detection - a document spawning a process, a legitimate program loading an unexpected library - is what covers the gap.
  • Disable Office macros by policy and treat exceptions as risk decisions. The entire chain here begins with a macro executing. Where macros are needed, the exception should be named, owned and reviewed.
  • Record vendor attributions with the confidence level attached. Medium confidence from one company is a different thing from a government attribution, and a ledger that loses the distinction will mislead whoever reads it in six months.
  • Watch the region rather than the incident. Governments in Central Asia and the South Caucasus are of interest to more than one external party, so an organisation operating there should plan against collection generally rather than against a named actor.
Sources

Compiled from open-source reporting for professional security discussion. This is a single security vendor's research finding. Bitdefender assesses the actor as China-nexus at medium confidence; that assessment has not been corroborated by another researcher or by any government, and no state has attributed the activity. The victim organisations have not been named beyond the countries concerned, and the count of infected machines is what the vendor was able to observe rather than a measure of the campaign. Technical indicators are not reproduced here. Details may be revised. This is a protective-security lessons-learned assessment, not an operational account.