2026-08-24NOTABLESilkParasite gets five named RAT families and one reusable detection: the side-loading pairing, not the DLL name
SilkParasite
campaign · campaign:silkparasite-central-asia-2026 single-source
Bitdefender Labs designation for a cyberespionage operation it assesses at medium confidence as China-nexus, targeting government bodies handling economic policy across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan and Georgia since roughly late 2025. Seven remote-access tool families are in use, five of them newly documented; command-and-control channels include a shared Google Drive folder and HTTP cookie and ETag header values, and the toolset carries indicators Bitdefender reads as AI-assisted development at medium confidence (Bitdefender Labs, 2026-08-19).
Coverage
2
1 about it · 1 mention · first 2026-08-23 → last 2026-08-28
Latest activity
2026-08-24
SilkParasite gets five named RAT families and one reusable detection: the side-loading pairing, not the DLL…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: apac, europe
Sources cited
2
2 hosts
2026-08-242 appearances2026-08-28
Defender insights
What each entry about SilkParasite tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- CookiETagRATBitdefender names CookiETagRAT among the cluster's seven families and documents its HTTP Cookie/ETag tasking channel
- DriveSilkRATBitdefender names DriveSilkRAT among the cluster's seven families and documents its Google Drive command-and-control channel
- GoginRATBitdefender names GoginRAT among the cluster's five newly documented families
- NodeEdgeRATBitdefender names NodeEdgeRAT among the cluster's five newly documented families
- NomadRATBitdefender names NomadRAT among the cluster's five newly documented families
Story timeline
Every entry that names SilkParasite, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-08-28Unit 42's dataset of 405 AI-enabled malware samples finds 97% never leave sandboxes, and every sample that reached a production environment was caught by existing behavioural detection with no novel approach required
- 2026-08-24SilkParasite runs seven RAT families behind six signed-application side-loading pairs, and the reusable detection is the pairing itself, not any DLL name: a signed binary loading a library placed beside it from an unusual location
Hunting pivots
ATT&CK techniques (8 across 4 tactics)
8 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing: Spearphishing Attachment
- ExecutionWindows Management Instrumentation · Hijack Execution Flow: DLL
- StealthObfuscated Files or Information · Hijack Execution Flow: DLL · Reflective Code Loading
- Command and ControlApplication Layer Protocol: Web Protocols · Web Service: Bidirectional Communication · Encrypted Channel: Symmetric Cryptography
Initial Access TA0001
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Execution TA0002
T1047Windows Management Instrumentation×1
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1573.001Encrypted Channel: Symmetric Cryptography×1
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Entries about SilkParasite (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bitdefender.com1 (50%)
- unit42.paloaltonetworks.com1 (50%)