ctipilot.ch

SilkParasite

campaign · campaign:silkparasite-central-asia-2026

Bitdefender Labs designation for a cyberespionage operation it assesses at medium confidence as China-nexus, targeting government bodies handling economic policy across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan and Georgia since roughly late 2025. Seven remote-access tool families are in use, five of them newly documented; command-and-control channels include a shared Google Drive folder and HTTP cookie and ETag header values, and the toolset carries indicators Bitdefender reads as AI-assisted development at medium confidence (Bitdefender Labs, 2026-08-19).

Coverage timeline
2
first 2026-08-23 → last 2026-08-23
Peak priority
notable
2 notable
Sources cited
9
9 hosts
Sections touched
1
weekly-research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
10
pinned v19.2 · see below
2026-08-232 appearances2026-08-23

ATT&CK techniques

10 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1596.005Search Open Technical Databases: Scan Databases×1

Adversaries may search within public scan databases for information about victims that can be used during targeting. Various online services continuously publish the results of Internet scans/surveys, often harvesting information such as active IP addresses, hostnames, open ports, certificates, and even server banners.

Evidence: 2026-08-23/weekly-w34-ai-bought-throughput-not-capability · ATT&CK page ↗

Resource Development TA0042

T1583.006Acquire Infrastructure: Web Services×1

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Evidence: 2026-08-23/weekly-w34-c2-rendezvous-moved-to-services-you-cannot-block · ATT&CK page ↗

T1584.006Compromise Infrastructure: Web Services×1

Adversaries may compromise access to third-party web services that can be used during targeting. A variety of popular websites exist for legitimate users to register for web-based services, such as GitHub, Twitter, Dropbox, Google, SendGrid, etc. Adversaries may try to take ownership of a legitimate user's access to a web service and use that web service as infrastructure in support of cyber operations. Such web services can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, particularly when access is stolen from legitimate users, adversaries can make it difficult to physically tie back operations to them. Additionally, leveraging compromised web-based email services may allow adversaries to leverage the trust associated with legitimate domains.

Evidence: 2026-08-23/weekly-w34-c2-rendezvous-moved-to-services-you-cannot-block · ATT&CK page ↗

T1585.001Establish Accounts: Social Media Accounts×1

Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used to build a persona to further operations. Persona development consists of the development of public information, presence, history and appropriate affiliations.

Evidence: 2026-08-23/weekly-w34-ai-bought-throughput-not-capability · ATT&CK page ↗

T1587.004Develop Capabilities: Exploits×1

Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits. Adversaries may use information acquired via Vulnerabilities to focus exploit development efforts. As part of the exploit development process, adversaries may uncover exploitable vulnerabilities through methods such as fuzzing and patch analysis.

Evidence: 2026-08-23/weekly-w34-ai-bought-throughput-not-capability · ATT&CK page ↗

T1588.007Obtain Capabilities: Artificial Intelligence×1

Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting Reconnaissance, creating basic scripts, assisting social engineering, and even developing payloads.

Evidence: 2026-08-23/weekly-w34-ai-bought-throughput-not-capability · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-23/weekly-w34-ai-bought-throughput-not-capability · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-08-23/weekly-w34-c2-rendezvous-moved-to-services-you-cannot-block · ATT&CK page ↗

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-08-23/weekly-w34-c2-rendezvous-moved-to-services-you-cannot-block · ATT&CK page ↗

T1102.002Web Service: Bidirectional Communication×1

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.

Evidence: 2026-08-23/weekly-w34-c2-rendezvous-moved-to-services-you-cannot-block · ATT&CK page ↗

Story timeline

  1. 2026-08-23Four unrelated disclosures this week put the command-and-control rendezvous on infrastructure that resolves correctly and cannot be reputation-blocked — a public blockchain contract, the Google Sheets API, GitHub Gists, an HTTP cache header, and two thousand hijacked WordPress sites
    weekly-researchThe C2 address is now stored somewhere legitimate and attacker-writable, so blocking the destination blocks a service you use
  2. 2026-08-23Four independent publications this week put AI inside the adversary's own workflow, and all four reach the same conclusion — it bought throughput and coverage against unchanged tradecraft, and it left provenance tells a defender can grep for
    weekly-researchAI is accelerating operations, not inventing techniques — and three labs published the tells it leaves behind

Where this entity is cited

  • weekly-research2

Source distribution

  • acronis.com1 (11%)
  • bitdefender.com1 (11%)
  • bleepingcomputer.com1 (11%)
  • blog.talosintelligence.com1 (11%)
  • ic3.gov1 (11%)
  • recordedfuture.com1 (11%)
  • redcanary.com1 (11%)
  • research.checkpoint.com1 (11%)
  • other1 (11%)

explore in graph

All cited sources (9)

Entries about SilkParasite (2)

2026-08-23 · view entry permalink →

NOTABLENATOB1

Four unrelated disclosures this week put the command-and-control rendezvous on infrastructure that resolves correctly and cannot be reputation-blocked — a public blockchain contract, the Google Sheets API, GitHub Gists, an HTTP cache header, and two thousand hijacked WordPress sites

A prior weekly carried a measurement of malware command-and-control that never asks DNS a question — traffic straight to an IP address, invisible to protective DNS, response-policy zones and sinkholing. Four disclosures this week describe the opposite arrangement and it is the harder one: the name resolves, correctly, to a service with a valid certificate and an unimpeachable reputation, because the operator has stored the actual rendezvous address inside something the estate already permits.

Red Canary's monthly round-up, published on July telemetry, is the clearest statement that this is no longer specialist tradecraft. Three of the four new entrants to its most-prevalent list resolve their command-and-control address from a dead drop rather than from a hardcoded domain or IP, and two of those read it off a public blockchain smart contract; the technique dates to first reporting in 2023, and what the round-up records is its arrival in commodity tooling, counted across three of its top ten this month (Red Canary, 2026-08-20). The mechanics decide what a defender can do about it. A macOS remote-access tool and stealer queries public Polygon RPC endpoints for a contract's stored value, decodes the response to extract a URL, and keeps messaging-platform and gaming-platform profiles as redundant dead-drop channels; a Node.js remote-access trojan polls public Ethereum RPC endpoints for a URL held at a predefined contract address; a third resolves its dead drop through a gaming-community domain or adversary-controlled hosts. Red Canary's own summary of why it matters operationally: "The technique makes traditional C2 blocking challenging, since the URL can be updated dynamically by adversaries" — the operator rewrites one contract value and every installation picks up the change with no redistribution.

The same architecture appears three more times this week on carriers that are not blockchains, which is what makes it an architectural pattern rather than a cryptocurrency story. Acronis's Threat Research Unit documents an espionage cluster running one implant's entire command-and-control through the Google Sheets API v4 using a hardcoded cloud service account and a per-victim spreadsheet tab, and a second implant doing the same job through GitHub Gists (Acronis Threat Research Unit, 2026-08-13). Bitdefender's SilkParasite disclosure records one family routing operator commands through a shared Google Drive folder and fetching in-memory plugins from it, and another using HTTP cookie and ETag header values as its command channel — a carrier that survives even a proxy inspecting request and response bodies, because the payload is in the caching metadata (Bitdefender Labs, 2026-08-19). And Check Point Research describes a criminal toolkit that dispenses with dedicated infrastructure altogether, hosting its payloads, command-and-control and stolen data on roughly 2,000 compromised WordPress sites, with persistence on each one as a must-use plugin in a directory WordPress auto-loads on every request and does not show in the plugin list (Check Point Research, 2026-08-18).

Four different carriers, one property: in each case the destination a network control can see is legitimate, and the address that matters is data held inside it, writable by the operator at will.

The technique makes traditional C2 blocking challenging, since the URL can be updated dynamically by adversaries

Red Canary 2026-08-20

Builds on: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin

research23 Aug 23:58Zmulti-sourceOpen finding ↗

2026-08-23 · view entry permalink →

NOTABLENATOB1

Four independent publications this week put AI inside the adversary's own workflow, and all four reach the same conclusion — it bought throughput and coverage against unchanged tradecraft, and it left provenance tells a defender can grep for

Prior weeklies tracked AI as an accelerant, then as an autonomous operator, then as a target in its own right. The 2026-W34 delta is a convergence: four unrelated publications inside one week look at AI inside the adversary's own operation from four different vantage points — recovered attacker artefacts, a five-agency advisory, an employment-fraud investigation and a malware-development analysis — and none of them finds a new technique. What each finds is more of an old one, delivered faster, and a residue that says so.

The recovered playbook. Cisco Talos recovered UAT-10147's own operational material from open directories on the actor's infrastructure — it reached one by following a compromised host's traffic to a download server, and attributes the target list to an open directory on the actor's command-and-control server: a target list of roughly 170,000 URLs split into seventeen files of about ten thousand each because scanning the whole list at once was inefficient, an AI-generated nine-section playbook for ASP.NET ViewState deserialization attacks, and four companion Python scripts automating write-capability testing, implant deployment, web-shell staging and reconnaissance (Cisco Talos, 2026-08-20). The initial-access set is a museum: a Zimbra flaw from 2022, an AjaxPro deserialization flaw and two Nacos flaws from 2021, and the 2019 Telerik UI deserialization bug. Every one is years old and patched. Talos assesses at moderate-to-high confidence that the actor belongs to an emerging class of financially motivated operators using agentic AI to operationalise offensive tradecraft at scale, and reports two AI tools on the actor's own infrastructure — a source-code vulnerability-scanning framework on its management server, of which Talos says at high confidence that the actor intends to use it against target website source code and third-party libraries, and an AI-driven penetration-testing tool on its command-and-control server, used to scan web servers and run proof-of-concept exploits.

The single most useful thing in that playbook is defensive and has nothing to do with AI. The document records that time-based blind testing cannot confirm ViewState code execution because the launch call returns immediately, which pushed the actor to out-of-band callbacks — and, more importantly, that a successful exploitation attempt surfaces as an HTTP 500 carrying a cast exception. Talos states the consequence: "This inverted success condition is a defensive blind spot: network monitoring tools that alert on 5xx responses may generate excessive noise, while the actual exploit succeeds silently in the error stream." Mature web-monitoring configurations suppress 5xx noise as a matter of course; against this technique that suppression filters out precisely the successful attempts.

The advisory. The NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency report actors using artificial intelligence to develop Python exploitation scripts built on snap7.dll and python-snap7 — the standard open-source means of speaking S7comm to a Siemens controller — and disguising those tools as legitimate OT monitoring software, with read and write access to PLC memory, configuration data and ladder-logic programs (BleepingComputer, 2026-08-19, reporting the joint advisory published at ic3.gov, 2026-08-19). The access path involves no novel vulnerability at all: controllers are located through commercial internet-scanning services, then attacked through known vulnerabilities, outdated software and weak authentication. The agencies characterise the activity as focused on persistent reconnaissance, potentially preparing for disruption — a statement about preparation, not about control-system manipulation having occurred.

The hiring pipeline. Insikt Group's PurpleDelta analysis quantifies the throughput directly: between late 2024 and early 2025 one cluster applied to jobs at over 1,100 companies, sometimes at a rate of at least 60 positions a day, running at least 22 fabricated personas (Insikt Group, 2026-08-18). AI is in two places in that operation and neither is a capability the operators lacked before: profile photographs come from a face-swapping service, and during live interviews the operators record and transcribe the call and feed the questions to purpose-configured chatbot assistants, reading the answers back — Insikt notes the answers were sometimes visibly wrong. That is the whole shape of the finding in miniature. The AI does not make the operator a better engineer; it makes it possible to be 22 people at once.

The malware. Bitdefender Labs disclosed SilkParasite, a cyberespionage operation it assesses at medium confidence as China-nexus, running seven remote-access tool families against government bodies handling economic policy across Central Asia and Georgia. Its summary of the toolset is the sentence to keep: "The toolset is small, modular, and professionally engineered, and it carries traces of AI-assisted development" (Bitdefender Labs, 2026-08-19). The tells are concrete and gradeable. One family ships Go test functions left inside the deployed binary — testing scaffolding normally stripped before release — and a hardcoded AES key set to 0123456789abcdef, a string so sequential Bitdefender reads it as a placeholder someone meant to replace; another carries an encryption-key configuration field still set to the literal change_this_key; and two families in different languages share an architecture close enough to suggest one high-level design implemented twice. Bitdefender is careful about what that adds up to: "SilkParasite is primarily assisted: capable humans do the engineering and lean on AI to move faster, leaving behind a few tells but none of the degradation."

Talos reached the same shape independently from the other direction, assessing at medium confidence that the SPECTRE Linux rootkit's source shows AI-assisted development — resting it partly on three redundant implementations explicitly labelled as alternative methods, where a human targeting one kernel would pick one. And a fifth dataset agrees: Sophos X-Ops, reviewing 38 confirmed adversarial-AI cases from a year of managed-detection casework, reports that where it saw attackers genuinely use AI as a capability, it was as an assistant with a human in control (Sophos X-Ops, 2026-08-19).

The toolset is small, modular, and professionally engineered, and it carries traces of AI-assisted development.

SilkParasite is primarily assisted: capable humans do the engineering and lean on AI to move faster, leaving behind a few tells but none of the degradation.

Bitdefender Labs 2026-08-19

This inverted success condition is a defensive blind spot: network monitoring tools that alert on 5xx responses may generate excessive noise, while the actual exploit succeeds silently in the error stream.

Cisco Talos 2026-08-20

Builds on: 2026-08-23/uat-10147-agentic-ai-exploitation-oob-confirmation · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-20/joint-advisory-active-threat-siemens-s7-plcs · 2026-08-19/purpledelta-dprk-it-worker-facilitator-rmm-detection

research23 Aug 23:56Zmulti-sourceOpen finding ↗