Cybersecurity researchers have uncovered a cyberespionage campaign targeting government bodies across all five Central Asian states, as well as Georgia. Bitdefender Labs discovered the campaign after detecting malware at an unnamed Central Asian government institution involved in economic decision-making.
Researchers later found malicious documents tailored to government targets in Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan, and Georgia. The documents were designed to look legitimate and trick recipients into opening files that could infect their computers.
Bitdefender has been tracking the campaign, dubbed SilkParasite, since late 2025 and assesses with medium confidence that it is linked to Chinese cyberespionage activity. However, the company has not identified a specific group behind the operation, nor does it claim Chinese government involvement.
How the Attack Works
The attackers appear to have gained access through targeted phishing emails containing malicious Microsoft Office documents, sometimes hidden inside password-protected archives. The password is supplied in the email, a technique that can make the attachments harder for automated security systems to inspect.
Once opened, the documents can run malicious code that installs software giving the attackers remote access to the computer.
Bitdefender found seven families of remote access trojans, or RATs, five of which had not previously been documented. RATs are programs that allow attackers to control an infected device from a distance, including running commands and accessing files.
One of the new tools, DriveSilkRAT, uses Google Drive to exchange data with an infected machine, allowing malicious traffic to blend in with traffic from a legitimate cloud service.
Bitdefender also found signs that artificial intelligence had been used to assist in developing some of the malware. However, the researchers say the software was primarily built by skilled human developers rather than generated by AI.
Why Bitdefender Points to a China Nexus
Bitdefender bases its China assessment on several technical clues. These include links between malware used by SilkParasite and tools previously associated with China-based espionage groups, as well as several IP addresses tied to China Unicom’s network. Researchers also found overlap with malware previously seen in the FamousSparrow campaign.
Martin Zugec, technical solutions director at Bitdefender, told cybersecurity news publication Dark Reading that the tools used in the campaign are designed to remain hidden and preserve long-term access. The attackers also use trusted services and legitimate applications, which can make malicious activity more difficult to detect.
Zugec argues that Central Asia has become a more important intelligence target as China’s economic role in the region has expanded.
What Is Known About the Potential Damage
Kazakhstan has already experienced a sharp rise in cyber incidents. Around 30,000 information security incidents were recorded in the first months of 2025, roughly twice the number reported a year earlier.
In May 2025, a large-scale DDoS attack disrupted access to government websites, banking services, and telecommunications networks.
SilkParasite represents a different type of threat. Unlike DDoS attacks, which are designed to overwhelm online services, the RATs identified by Bitdefender are designed to gain and maintain remote access to compromised systems.
Bitdefender has not disclosed what information, if any, was taken from the unnamed government institution that led to the investigation. It has, however, observed roughly 65 DriveSilkRAT infection instances, mostly in Asia. The company cautions that this is an upper estimate rather than a confirmed number of infected computers, as a single machine can generate more than one identifier.
For now, researchers know far more about how SilkParasite operates and whom it targeted than about what information, if any, the attackers obtained.
