China’s ‘SilkParasite’ Espionage Campaign Targets Central Asian Governments with AI-Enhanced Malware

Published:

spot_img

Five previously undocumented strains of malware are being used in attacks on government bodies across Central Asia, according to a report by cybersecurity company Bitdefender. The espionage campaign, dubbed “SilkParasite,” is believed to be orchestrated by military-grade hackers based in China, who have utilized artificial intelligence throughout the malware development process.

Bitdefender’s investigation began with a suspicious infection at a government institution related to the economy in an unnamed Central Asian country. Over several months, researchers uncovered seven malware families and identified that the operation had been ongoing for nearly a year. The malware was found in malicious documents designed to appear relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan, with several documents impersonating ministries.

The report suggests that the decline of Russia’s influence in Central Asia has created an opportunity for China to expand its economic reach, prompting espionage activities targeting the economic sectors of these governments. Bitdefender linked the campaign to China through connections between at least one malware strain and another known China-based espionage group. Additionally, several IP addresses associated with the campaign were traced back to Chinese telecommunications companies.

Malware Delivery and AI Integration

The hackers gained initial access through malicious Microsoft Office documents, typically delivered via spearphishing emails. These lure documents were often packaged in archives to evade email-gateway scanning. Bitdefender reported 65 infections, primarily in the Asia region, with DriveSilkRAT being the most prevalent of the seven malware strains identified. Notably, DriveSilkRAT does not communicate with a dedicated command and control server; instead, it connects to a shared Google Drive folder, allowing it to blend in with normal traffic and evade detection.

Artificial Intelligence in Cyber Espionage

A significant aspect of the SilkParasite campaign is the integration of artificial intelligence. Bitdefender found that two of the email lures were generated by AI, and evidence suggests that AI was used in the development of the malware strains, five of which had not been previously documented. The campaign exemplifies professional espionage tooling optimized for minimal footprint and dynamic execution, with code designed to avoid resembling earlier malware families.

Bitdefender emphasized that while AI plays a role in the development process, the malware remains the product of skilled human professionals. The report indicates that even sophisticated state-backed actors are beginning to adopt AI-assisted coding practices. This trend aligns with recent warnings from the National Security Agency about the use of AI-generated exploit scripts targeting critical infrastructure, highlighting the evolving landscape of cyber threats.

For more details, refer to the full report by The Record.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

Qatar’s Cyber Security Agency warns Mac users of critical malware vulnerability

Doha, Qatar: The National Cyber Security Agency (NCSA) has issued a critical alert for Apple Mac users in Qatar regarding a significant vulnerability in...

Hackers Actively Exploiting Recently Patched Zimbra Collaboration Vulnerability CVE-2026-73570

A recently patched Zimbra Collaboration vulnerability is being exploited in the wild, according to Poland’s CERT Polska. The security hole, tracked as CVE-2026-73570, was addressed...

Cisco Security Advisory AV26-834 Warns of Vulnerabilities in Multiple Products

Advisory Number: AV26-834Date Issued: August 20, 2026 Cisco has issued a security advisory regarding vulnerabilities affecting several of its products, as of August 19, 2026....

Public Cyber Benchmarks Risk Misleading AI Performance in Cybersecurity

In the realm of artificial intelligence (AI) and cybersecurity, public benchmarks serve as critical tools for assessing performance, validating model updates, and fostering industry...