SilkParasite: New Espionage Group Hits Central Asian Governments With Five Unseen Hacking Tools
Researchers have named a fresh spying operation running seven remote-access tools against government offices across the region, five of them never seen before.

Key points
- A newly named espionage operation called SilkParasite is targeting government bodies across Central Asia, according to research surfaced in late 2025.
- The group is running seven remote access tool families: malicious programs that let attackers control a machine from afar.
- Five of those tools haven't been publicly documented before: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT.
- The activity is assessed as cyber espionage, meaning theft of information rather than money or disruption.
- No public advisory, sanctions listing or formal government attribution has been issued at the time of writing.
A quiet spying campaign against Central Asian government offices has been given a name: SilkParasite. Researchers say the operation runs a custom toolkit built to sit inside official networks and pull data out, first spotted in late 2025.
It hasn't been the subject of a public advisory from a national cyber authority or a sanctions action, which are the usual formal markers of state-level attribution. Public reporting names the region and the target sector but not specific ministries or countries.
Who is SilkParasite and what did they do?
SilkParasite is the label researchers have given to a previously unreported intrusion set targeting government bodies in Central Asia. It's assessed as cyber espionage, the quiet theft of sensitive information from official systems. This fits a pattern we've followed since July: Chinese-speaking hackers hit the same region on 31 July using two custom malware families tracked as OctLurk and SilkLurk, and SilkParasite is now the second such campaign we've reported against Central Asian governments in six weeks.
What are these seven tools?
They're remote access tools, or RATs: malicious programs installed on a victim's machine that give the attacker a hidden back door to run commands and read files. Five of the seven families are newly documented, which is unusual. Most espionage crews reuse existing code, and building this many bespoke tools points to a well-resourced operator.
| Tool name | Status |
|---|---|
| DriveSilkRAT | Newly documented |
| CookiETagRAT | Newly documented |
| NomadRAT | Newly documented |
| GoginRAT | Newly documented |
| NodeEdgeRAT | Newly documented |
| Two further RATs | Previously known families |
Should ordinary people in the region be worried?
Not directly. This campaign is aimed at government networks, not consumer accounts or banking apps, and there's no indication citizen data has been dumped online or sold. Espionage crews that break into government departments do pick up personal information along the way, though: identity documents, tax records, correspondence with officials. Anyone who's filed paperwork with a government body in the region should be alert to unusual contact that quotes real details from past dealings, a classic sign that stolen records are being recycled for follow-on scams.
What happens next on the policy side?
Expect national computer emergency response teams in the region to issue technical bulletins with indicators of compromise: the digital fingerprints defenders use to search their own networks. Whether any of the affected states makes a formal public attribution, or coordinates with partners on sanctions, is a separate political question and hasn't happened yet.
For readers outside the region the practical observation is narrow but worth stating plainly. When a single crew shows up with five new custom back doors at once, detection based on known malware signatures alone won't catch it. Behaviour-based monitoring, looking for what a program does rather than what it's called, is what finds this kind of tooling early. That's the lesson from SilkParasite, and it's the same lesson from every newly-named crew that lands without a prior fingerprint on file.



