Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

SilkParasite: Tracking a China-Nexus APT Across Central Asia

0
Medium
Published: 08/20/2026 (08/20/2026, 07:04:46 UTC)
Source: AlienVault OTX General

Description

SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 08:42:28 UTC

Technical Analysis

SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus, targeting government bodies in Central Asia. It deploys seven remote access tool families, five of which are newly identified: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is modular and professionally engineered, with signs of AI-assisted development. Initial access is gained through malicious Microsoft Office documents delivered via spear-phishing campaigns using regionally tailored lures impersonating government ministries. DLL sideloading is the primary delivery mechanism, and Google Drive is leveraged for command-and-control communications to blend within trusted services. Infrastructure analysis reveals links to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and strong operational security.

Potential Impact

The operation targets government bodies in Central Asia for cyberespionage purposes, potentially leading to unauthorized access to sensitive government information. The use of multiple sophisticated remote access tools and evasion techniques like DLL sideloading and trusted cloud services for command-and-control increases the difficulty of detection and mitigation. The campaign's professional development and operational security indicate a persistent threat capable of sustained espionage activities.

Defensive Guidance

No specific patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear-phishing attempts, monitoring for DLL sideloading behaviors, and scrutinizing unusual use of trusted cloud services like Google Drive for command-and-control. Employing threat intelligence to identify indicators related to SilkParasite and enhancing email security controls are recommended. Since no official vendor advisory or patch exists, continuous monitoring and incident response preparedness are essential.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia"]
Adversary
SilkParasite
Pulse Id
6a86a70eb8b57f155e62d4f7
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash41a995491ef98e4b8a794cde3ad3cdaa269df16e7b7bfa1bdc898a2239db6465
hash022287b05e4c5ba5503f2b798219f5e9
hash0287ba0ecc176ae63ea1d1e053654f32
hash09e12d8143dc4ccefe2b9ff4858383fa
hash0fa04679a1121eec0442fbad1a8fe69f
hash1100e1d599b5e4f87082670673c8abfb
hash15c839292684ac6374633d231dbd76a7
hash17134fe1344744cf99a93483f6859212
hash17dc3ad572ba5b275e545e7498ee129b
hash182c9cca16e16a8621e6691e003e7717
hash22573d874ac9ffa785e57d94e243b48d
hash25743698d03b1724415781b777687a6e
hash275cc2c1b0d53f43d49374494bd14724
hash2d7bbf3a52a3f2410f6f87836e0d853d
hash3746d143bb695446249541ca3cfd2e70
hash391f30807d3cf333cdc286d1ff5b0f58
hash3d1dafe83b4b37c849c3994ccced5bc1
hash3eb0b0811c0ab9e87e2ee7f7bac7c46a
hash3f0c18f8289a6cbc800696ac5b6c3246
hash4395e8e7351de03faac54492ee2bc874
hash43964960ec5d070b933429fed10fd8cd
hash45457100c94d8bb0c74734d5dd8faa30
hash4a10caea74246763ddeb92313dc71b3e
hash4c97d3b20b51f1b66632d726682e617e
hash60f77706dbb3c7160a05fc0372c799ad
hash640fb756e8de75161e17743e350e0898
hash68441c32dc0c49b9a32fe0fc38fb0ec9
hash77dc27fb2ed18f3977241e9475097746
hash7b00beb5a7ef4a142ebcdcc052b312a3
hash7e27fa3a4813d6ecc3246c66596c79c9
hash819dbc6a3c1c2ecdc461d9c4bb9e1e42
hash827c80b37fa741732c6cd3f3fdfbfe7a
hash84533ef6651f38fe162ad2753f1ad788
hash85a62cf36b1c0445ac8c4a57b18adb8a
hash86a164a403a94c8ccd4f0ba383fa943c
hash906e49f334041ebccc071985ecdcf2ba
hasha1728ff6b393d622e114679bfc812d09
hasha3529670e6470ca1505cb5ab9cbadbac
hasha626a63ee577558d24df8683748b09c7
hashac5d9d4019db3a51d7960e50c3302c06
hashb2c1e7263ec4dcb24d3524e10f3b5f5c
hashb44a3229ab54f7367ee2acd678bec2d5
hashbe3bc9e6565f95afe57eee324f9b8e4e
hashd5a02c94b6842a70b73e42e089c0bc1b
hashd6382cef53530b79cf4517c166724d67
hashe0b008ea6eef411ed6f9faab8f1d3bee
hashe7e39e318ffe641dbea34ae59f80420d
hasheef9fe0c9619b75b9553243fd19709e4
hashf6b126c83ea4a63f277199d7c06617d6
hashf7192d9c0902c24937eadedc4c49ed10
hashff33a3be2d497d934b88c8d9e0135d6b
hash5d8d9ce63d63f5d89b3774215830751de6efced2
hashd2d17b29617633d61875bfa00c76556fa39f9ce1
hashe84c8a7a49bca65c193ea60a3ecb26eb97bd3cfe
hash19ceadf6459625d5132e0a1e61ec5c4eda890ba9841c415389c2957af40159a7
hash1b6bc5cd16fa1d76a7b97b671dc8d280ea4fd6fd377f18cb963ca2510189554b
hash1ee70564c07bf9b66b9759f34178e3b9cce37a4fb87d3917705e7294a0f0703a
hash22c055eea87fffb85ebb9eae219b7f9156907b1629a378d67b2a3265f48667b6
hash23dbe77c5371a193685048291a2a63d80dd47fa49e6918d50c44a1a4bc1ecc41
hash2509d7e517d6b2b740d2e04a4c1caffe0dc741be13611803b3f679e4636f84e2
hash262ec227d7650265cbe27874acf6482a16903cdb94a4824ab22e8b88400b23af
hash27aff4ddd2b873426bbf9c5e854761a29575d55ea1b90fa767592a409e504667
hash29276db7153071d7cfeea3e18cd93c7b1f4e16c7a8bdb0a908aab5670fe5f448
hash38a113e6254f89fb0cf339eda18a81410a1dab074eeaf3a2a7c1f086feee0260
hash4fc2b279444cc7d4b77e2dbfe5396525f184b5b422904a559849da86539bf505
hash585e152b25ce26a99912d73eb18de67c5cfbd3f13897197a104d09f9b5a71836
hash62754cd27e27044ffc2a4c5d3b2959bc7c373f339e3388b2ac1b9a929c04a9a4
hash67fffd05419913afb7611eefc684b152304d2bf875f13cd6acb0734c506481a5
hash6b670760e3fc5e4cc39a6702d2e3cce2fe112282a7314bb8827942b84ea7cc4b
hash6f1ee23e0458f0ed539563f0694ab0ad74977fa625a396ee3ad0fac4d0f1c21b
hash7392796a71fa92962277d4f8a10b9a61d2ed7e8428c82da6f9b0629640f583e7
hash7b172a111d0170aed9e8235782abf7b4a6a70a2c8eeec88bb6001592119da1dc
hash7c4ac90c1f79b15f701adef322043dd0f6f3223c08d018069c1015a5c1aa40e8
hash82b701084f419d97f52b459e0e314b61672685f60ecbab6c19c10c2160f08954
hash85ad3ce3a99fa606b5c260328c8a0bfac8b5483cb9a179c68e625b20bead7517
hash872becaf15bcbc75975f584940d34ee82cd77e1e0f600907bc53c7a47f2b5e87
hash93e12c8d554a9a92e13bdfae47bdd12bc2fca61493471812a4e4b6df08b95407
hash95700c5258268957997357c813272f7b6e2bd4bd7bcb5915e91d123ebef93d1c
hash9dcf6a2540467629d59cce9e29875ddbc6979796efc3f595129b2e28e5ade2f6
hasha1784169dd84cf886ed75219a32ffde24e93bca7650dafd6a51a9062f52f7f35
hasha371ede857979587f1dca717f26a0e9259a15a51f4e7bb810d32b099ae95a650
hasha3a41698893bfce0e4a43e6c1ff9f59b579d3619f85d081c8165898cfca0001f
hasha4fa32bb75a4bbcc82c398591a1de5a76ef93cedaffd719f43972ce3105f2892
hasha589730b8c70136e2047ee25e6128f87bbe6d4118ee833196c2e7616decd5975
hashaab828ceb2db599e5fd2f9a742645dcf17eeac3b3e322d71fe068ea74dfc7fba
hashaff1cc88c2c28bd9f62812b2cae971cca0342901f653612ff7031da67afd5716
hashb97b4ad9bfd11bacd1afe15b8e1b9286811e612b732e0fd1003ac2e8474f9f30
hashba7eea1fe3ededc39ecd7524e956630d61ef509e814ba409afbc0100b316cdea
hashbac61aec1792898f898ce7ab528f9853337fa989768f25776f3865d53ac520d9
hashc19a1bfb076c8888bc1ea332e0c5cc2261d0f5bd60cee84ec864ee16c6d24611
hashcd6e8fb4a12ddd94b96f33ebcaaf9d7fbd77f62c98991a24287d14df8a2be7d1
hashcee43b4f904e376999d6f4db5f4fd6d158e2aa0d412896bdb9d3e62ecaf71c0b
hashd16507495078941d106e4de52606bf573548e2b2125ee35d21b4b639b1001219
hashd1f49a4a97175315975eb74e61e0dc72c99528b2cb278f62bf3759df30543727
hashe50f8cdab370b0b444400028e7160b16f8fe6a15b3c713b5ce8d16cae6b19eb6
hasheaed7c21ddcfc861dbee8d95a56fc4000f254bdc79baae244ecf9d3aa2220e70
hashf12166a7bbbb493605654dd2edee8d86a7ae064ea066285502f437c3a6810a2e
hashf338f32fa7524b9d46ec3b38f14bd807ed02d20713170ecd46c581b3401e4a23
hashf45130ffa7812972631aaa8ae5402bd6b137ea0340e9ab08ff28c61b75069089
hashfa5098ae87f3f91731be96a964dbebe76fbe710c6a281df68fdd85afe4d91a1b
hashfe60afdda38902c1499b3c872f492c796f380d9bde2fadb28315e3d3c35be8c5
hashff22419b8ec3994542f23c78dc21a7c5abcb634008d99b7fa1fff1bb23102a00

Domain

ValueDescriptionCopy
domainuzrailway.devon-uz.com
domainevo.hoster-kg.com

Ip

ValueDescriptionCopy
ip193.29.56.216

Url

ValueDescriptionCopy
urlhttps://uzrailway.devon-uz.com

Threat ID: 6a86b942acd9273b4955b89d

Added to database: 08/20/2026, 08:22:26 UTC

Last enriched: 08/20/2026, 08:42:28 UTC

Last updated: 08/20/2026, 12:48:35 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses