SilkParasite: government networks in five Central Asian states and Georgia
Bitdefender has published a campaign it calls SilkParasite, running against government bodies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan and Georgia since late 2025 and still active this month.
Seven families of remote access software, five of them newly named. Two details are worth more than the tool count: the lure documents impersonated specific ministries in each country, and the macro checks whether Kaspersky is running before it acts, and adapts its behaviour accordingly.
↓ Download one-page brief (PDF)A password-protected archive arrives
The initial approach is spear-phishing carrying a RAR archive with a password. The password is the point: an encrypted archive cannot be inspected by a mail gateway or scanned on arrival, so the file reaches the desktop intact and the recipient supplies the key.
The lure is written for the ministry it is sent to
The recovered documents were tailored to each country, several impersonating specific ministries, with a further document addressed to a Georgian government entity recovered from a public malware-sharing platform rather than from a victim. That is targeting research done before the first email is sent.
The macro checks the room before it acts
Before executing, the macro establishes whether Kaspersky's process is running on the machine and adapts its behaviour accordingly - not merely aborting, but changing what it does. Kaspersky is widely deployed across the region, so this is a defensive-estate adaptation rather than generic evasion.
The tools are side-loaded rather than installed
The macro triggers a sequence that loads the remote access software through a legitimate program rather than by installing something recognisable of its own. What runs on the machine then provides process listing, file handling, command execution and the ability to load further modules.
Seven families, five of them new
The campaign uses seven distinct tool families, of which five had not been documented before and two were already known. That breadth is unusual and it multiplies the work required of any defender trying to detect the activity by signature.
Roughly sixty-five machines, and a disclosure
Bitdefender observed about 65 machines carrying the principal tool and published on 19 August. The count is what the vendor could see, not necessarily the extent of the campaign.
Between three interests at once
The five Central Asian republics and Georgia sit on energy routes and infrastructure corridors of interest to China, to Russia and to Europe. Governments there hold negotiating positions, contract terms and internal assessments that several external parties would find useful.
Why a password defeats the gateway
Mail security inspects attachments. An encrypted archive cannot be inspected, and supplying the password in the message body transfers the decryption to the recipient, past the control. It is an old technique and it continues to work.
Antivirus as a targeting signal
A macro that looks for one specific product before acting tells you the operator has a view of the estate. Kaspersky is widely deployed across the former Soviet space, so checking for it is a regional adaptation rather than a generic evasion.
What the attribution actually rests on
Bitdefender cites a technical overlap - one SilkParasite tool resembling a backdoor used by the China-aligned FamousSparrow - together with DLL side-loading as a delivery method common among Chinese actors, and a strategic rationale: as Russian influence in Central Asia and the South Caucasus has receded since the war in Ukraine, Chinese economic engagement has increased and collection follows commerce. That is a reasoned case rather than an assertion, and it is still one company's assessment at medium confidence.
Two things should be held apart here. That the campaign exists and compromised government machines is vendor-documented and specific. That it is Chinese is one company's medium-confidence judgement, and a reader who carries the first forward as established and the second as equally solid will have imported an attribution nobody has stood behind.
The antivirus check is the most revealing detail in the disclosure
A macro that establishes whether one particular product is present before executing indicates an operator who has studied the defensive estate of the region it is working in, and who has decided how to behave when that product is found. That is target-aware tradecraft rather than commodity malware, and it is more informative about the actor's maturity than the number of tool families.
Password-protected archives remain effective because the control cannot see inside them
Encrypting an attachment and supplying the password in the covering message defeats gateway inspection by design, and the recipient completes the attack by decrypting it. It is not a sophisticated technique. Where an organisation permits encrypted archives to arrive by mail, it has accepted that a class of attachment will not be inspected, and that is a policy decision more than a technical one.
The AI finding is narrower than the headlines around it, and more interesting
Bitdefender describes traces of AI-assisted development running through otherwise expert code, and is explicit that this is a different thing from AI-generated malware: the toolset has the hallmarks of professional tooling built by human operators, with AI apparently used to streamline the work rather than to produce it. The distinction matters because the two produce opposite signatures - generated malware tends to be voluminous and undisciplined, while this is small, modular and deliberately built not to resemble earlier families. The clearest AI artefact the researchers point to is a phishing lure, not the malware.
Five new families in one disclosure is a statement about resourcing
Maintaining seven tool families, five of them unknown until this month, requires sustained development rather than a purchased kit, and Bitdefender records this as the third operation it has observed against this region after UAC-0063 and FamousSparrow. It is a realistic possibility that this reflects a state-resourced programme.
The attribution has a stated basis, and it is still one vendor at medium confidence
The reasoning is set out rather than asserted: a tool resembling a FamousSparrow backdoor, side-loading consistent with Chinese tradecraft, and a regional context in which Chinese engagement has grown as Russian influence has receded. No government has attributed the activity and no second researcher has corroborated it. The disciplined entry records a documented intrusion set against six named governments with a reasoned but uncorroborated attribution attached, and does not firm that attribution up by repeating it.
Collection against these governments will continue
The region's position between larger interests, its infrastructure exposure and the modest defensive capability of several of the states concerned make it a durable target. It is highly likely that spear-phishing with weaponised Office documents remains the principal route into government networks across the region, because it continues to work.
Set this beside Jewelbug, disclosed five days earlier and also assessed as China-nexus. Bitdefender is explicit that these are separate campaigns with separate toolsets. The temptation to merge two vendor disclosures about one country into a single picture is exactly what an analyst should resist, because the result is a composite adversary that does not exist.
- Decide your policy on encrypted archives arriving by mail. If a password-protected attachment cannot be inspected, permitting it is a decision to let an uninspected file class through. Blocking it, quarantining it or requiring detonation are all defensible; doing nothing is not.
- Assume an adversary knows which security products you run. This macro checked for one specific vendor. Procurement is often public, particularly in the government sector, and it should be assumed to be known.
- Do not rely on signatures for a campaign that is still being documented. Five of these seven families were unknown until this month. Behavioural detection - a document spawning a process, a legitimate program loading an unexpected library - is what covers the gap.
- Disable Office macros by policy and treat exceptions as risk decisions. The entire chain here begins with a macro executing. Where macros are needed, the exception should be named, owned and reviewed.
- Record vendor attributions with the confidence level attached. Medium confidence from one company is a different thing from a government attribution, and a ledger that loses the distinction will mislead whoever reads it in six months.
- Watch the region rather than the incident. Governments in Central Asia and the South Caucasus are of interest to more than one external party, so an organisation operating there should plan against collection generally rather than against a named actor.
- https://www.bitdefender.com/en-gb/blog/businessinsights/silkparasite-tracking-china-nexus-apt-across-central-asia
- https://thehackernews.com/2026/08/silkparasite-espionage-campaign-targets.html
- https://www.govinfosecurity.com/china-linked-apt-uses-ai-to-optimize-hand-built-malware-a-32597
Compiled from open-source reporting for professional security discussion. This is a single security vendor's research finding. Bitdefender assesses the actor as China-nexus at medium confidence; that assessment has not been corroborated by another researcher or by any government, and no state has attributed the activity. The victim organisations have not been named beyond the countries concerned, and the count of infected machines is what the vendor was able to observe rather than a measure of the campaign. Technical indicators are not reproduced here. Details may be revised. This is a protective-security lessons-learned assessment, not an operational account.