SilkParasite: New Espionage Group Hits Central Asian Governments With Five Unseen Hacking Tools

Researchers have named a fresh spying operation running seven remote-access tools against government offices across the region, five of them never seen before.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge overhead photoreal view of a dimly lit security operations center desk, multiple monitors showing abstract network graphs and IP address
Share

Key points

  • A newly named espionage operation called SilkParasite is targeting government bodies across Central Asia, according to research surfaced in late 2025.
  • The group is running seven remote access tool families, malicious programs that let attackers control a machine from afar.
  • Five of those tools have never been publicly documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT.
  • The activity is assessed as cyber espionage, meaning theft of information rather than money or disruption.
  • No public regulatory filing, sanctions listing or formal government attribution has been issued at the time of writing.

A quiet spying campaign against Central Asian government offices has been given a name: SilkParasite. Researchers say the operation has been running a mixed toolkit of custom malware built to sit inside official networks and pull data out.

The campaign was first surfaced in reporting by The Hacker News. It has not, so far, been the subject of a public advisory from a national cyber authority or a sanctions action, which are the usual formal markers of state-level attribution.

Who is SilkParasite and what did they do?

SilkParasite is the label researchers have given to a previously unreported intrusion set seen hitting government bodies in Central Asia. The group is assessed to be conducting cyber espionage, the quiet theft of sensitive information from official systems, rather than ransomware or destructive attacks.

The activity was first spotted in late 2025. Public reporting so far names the region and the target sector, government, but does not name the specific ministries or countries affected.

What are these seven tools?

They are remote access tools, or RATs: malicious programs installed on a victim's computer that give the attacker a hidden back door to run commands, read files and move around the network. Think of a RAT as a spare key the intruder cuts for themselves once they are inside.

SilkParasite is using seven such families. Five have never been documented before, which is unusual: most espionage crews reuse code, and building this many bespoke tools points to a well-resourced operator.

Tool name Status
DriveSilkRAT Newly documented
CookiETagRAT Newly documented
NomadRAT Newly documented
GoginRAT Newly documented
NodeEdgeRAT Newly documented
Two further RATs Previously known families

Should ordinary people in the region be worried?

Not directly. This campaign is aimed at government networks, not consumer accounts or banking apps, and there is no indication so far that citizen data has been dumped online or sold.

That said, espionage crews that break into government departments often pick up personal information along the way: identity documents, tax records, correspondence with officials. Anyone who has filed paperwork with a government body in the region should be alert to unusual emails or phone calls that quote real details from past dealings, a classic sign that stolen records are being reused for follow-on scams.

What happens next on the policy side?

Expect national computer emergency response teams in the region to issue technical bulletins with indicators of compromise, the digital fingerprints defenders use to search their own networks. Whether any of the five Central Asian states makes a formal public attribution, or coordinates with partners on sanctions, is a separate political question and has not happened yet.

For readers outside the region, the useful takeaway is narrower. When a single crew shows up with five new custom back doors at once, it is a reminder that detection based on known malware signatures alone is not enough. Behaviour-based monitoring, looking for what a program does rather than what it is called, catches this kind of tooling faster.

© 2026 Threat Vectr