2026-08-24NOTABLESilkParasite gets five named RAT families and one reusable detection: the side-loading pairing, not the DLL name
GoginRAT
malware · malware:goginrat single-source
Go-based orchestrator newly named by Bitdefender in its 2026-08-19 SilkParasite reporting, deployed by DLL side-loading beside a still-unidentified signed host application. Ships with leftover Go test functions and a hardcoded placeholder AES key, two of the code-level indicators Bitdefender reads as AI-assisted development at medium confidence (Bitdefender, 2026-08-19).
Coverage
1
first 2026-08-24 → last 2026-08-24
Latest activity
2026-08-24
SilkParasite gets five named RAT families and one reusable detection: the side-loading pairing, not the DLL…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: apac, europe
Sources cited
1
1 hosts
Defender insights
What each entry about GoginRAT tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
used by
- SilkParasiteBitdefender names GoginRAT among the cluster's five newly documented families
Story timeline
Hunting pivots
ATT&CK techniques (8 across 4 tactics)
8 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing: Spearphishing Attachment
- ExecutionWindows Management Instrumentation · Hijack Execution Flow: DLL
- StealthObfuscated Files or Information · Hijack Execution Flow: DLL · Reflective Code Loading
- Command and ControlApplication Layer Protocol: Web Protocols · Web Service: Bidirectional Communication · Encrypted Channel: Symmetric Cryptography
Initial Access TA0001
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Execution TA0002
T1047Windows Management Instrumentation×1
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
T1573.001Encrypted Channel: Symmetric Cryptography×1
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Evidence: 2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2 · ATT&CK page ↗
Entries about GoginRAT (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bitdefender.com1 (100%)