• KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
  • KZT/USD = 0.00219
  • TJS/USD = 0.10810
  • UZS/USD = 0.00009
  • TMT/USD = 0.29850
21 August 2026

Viewing results 1 - 6 of 1

Central Asian Government Agencies Targeted in New Cyberespionage Campaign

Cybersecurity researchers have uncovered a cyberespionage campaign targeting government institutions in Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, and Uzbekistan. Bitdefender Labs confirmed the compromise of one government institution in Central Asia involved in economic decision-making and discovered lure documents prepared for government agencies in all five countries in the region. The company has not disclosed which institution was compromised or whether any data was stolen Bitdefender has been tracking the campaign, dubbed SilkParasite, since late 2025 and attributes it with medium confidence to China-nexus activity. This is not the same as establishing the involvement of the Chinese authorities: the researchers provide no such evidence. At the time of publication, no public statements from Central Asian authorities confirming damage from SilkParasite could be found. How SilkParasite Was Discovered The investigation began after an infection was identified at a government institution in Central Asia. Analysis of the infrastructure and malware led researchers to lure documents intended for government organizations in Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, and Uzbekistan. Another lure was prepared for a target in Georgia. The existence of these documents indicates the range of potential targets but does not prove that all the intended organizations were successfully compromised. The published research confirms an infection at only one government institution. Dark Reading also reports that the campaign targeted government organizations in all five countries, but not that each of them was successfully breached. Researchers discovered seven families of remote access trojans, or RATs, five of which had not previously been documented. Such tools allow attackers to execute commands on an infected device, work with files, and maintain access to the system. One of the new tools, DriveSilkRAT, uses Google Drive to exchange data with an infected machine, allowing some malicious traffic to be disguised as communication with a legitimate cloud service. Bitdefender also found signs that artificial intelligence had been used as an auxiliary tool in developing the code. According to the researchers, most of the software itself was created by skilled developers. Why Bitdefender Points to a China Nexus Bitdefender links SilkParasite with medium confidence to broader activity previously tracked as FamousSparrow and points to technical connections with tools that researchers have previously associated with China-nexus groups. Martin Zugec, technical solutions director at Bitdefender, told Dark Reading that the tools used in the campaign are designed to remain inconspicuous and maintain long-term access. In particular, the attackers use trusted services and legitimate applications, which can make malicious activity more difficult to detect. Zugec links the presumed attackers’ interest in Central Asia to the region’s growing economic and geopolitical importance to China. This is the researcher’s assessment of possible motivation, not proof of the operation’s origin. Neither Bitdefender nor Dark Reading claims that the campaign was directed by the Chinese government. What Is Known About the Potential Damage Kazakhstan has already been experiencing high levels of cyber activity. In the first months of 2025, the country recorded around 30,000 information security incidents, roughly twice as many as a year earlier. Cases involving botnets increased particularly...