SilkParasite is a China-nexus APT campaign targeting Central Asian government bodies involved in economic policy. The operation deploys seven RAT families, five newly named, delivered primarily through DLL sideloading of signed legitimate applications. DriveSilkRAT serves as the backbone, using Google Drive as a C2 channel to route tasking through trusted cloud infrastructure. The toolset exhibits modular plugin architectures across four programming languages, maintained build infrastructure, and traces of AI-assisted development. Initial access uses spear-phishing emails delivering password-protected RAR archives containing malicious Office documents with regionally tailored lures.
China-Nexus APT
1 post
SilkParasite: Tracking a China-Nexus APT Across Central Asia