Infected Industries Threat Report #2138 tracks SilkParasite, a newly identified China-nexus espionage set active against Central Asian government targets since late 2025. The cluster leans on spear-phishing and a modular RAT stack that includes multiple previously undocumented families.
Executive snapshot
SilkParasite is assessed as a high-severity cyber espionage intrusion set. Public reporting links the activity to the FamousSparrow cluster. Campaigns emphasize geopolitical collection rather than smash-and-grab ransomware, with long-term persistence and data exfiltration as the operating goals.
In SAI, the linked entity set for this report includes more than 100 indicators, dominated by high-risk hash IOCs, with supporting domain, IP, URL, and process context. Defenders should treat the hash corpus as immediately actionable while building durable detections around spear-phishing delivery and RAT communications.
Threat actor profile
SilkParasite was first observed in late 2025 and remains active into August 2026. Origin is assessed as China. Primary victims are government bodies and related organizations across Central Asia.
The toolset is notable for engineering quality and modularity. Operators have used at least seven remote access tool families, including five previously undocumented variants: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. That mix supports staging, lateral movement, and long-dwell collection without depending on a single implant brand.
Attack path
- Initial access through tailored spear-phishing into target networks.
- Deployment of one or more RAT families for command and control and host control.
- Persistence and quiet collection against government and adjacent organizations.
- Ongoing indicator churn as new hashes and supporting infrastructure appear in open reporting and internal enrichment.
MITRE technique mapping in the current SAI report is still thin, so prioritization should follow observed behaviors: phishing-driven footholds, multi-RAT execution, and outbound C2 patterns consistent with espionage tooling.
What defenders should do now
Start with the confirmed high-risk hash set and the published true-positive hash context from the report. Automate alert routing for those IOCs into your SIEM and EDR, then promote matching entities into SAI Secure for enrichment and disposition.
In parallel, harden the phishing surface: tighten mail filtering, raise user reporting, and hunt for post-delivery execution that drops or launches RAT loaders. Network detection should watch for beaconing and remote access patterns that do not match approved admin tooling.
Control priorities that align with this campaign include account management, malicious code protection, incident handling, and boundary protection. Treat RAT sightings as incident-grade events even when encryption or extortion is absent.
Operationalizing in SAI Secure
Use the threat report entities as the seed set. Enrich hashes and supporting infrastructure, classify confirmed true positives, and push detections into the platforms your SOC already runs. Pair the short-lived hash sweep with behavioral hunts for spear-phishing follow-on activity so coverage survives the next implant rename.
Conclusion
SilkParasite is a reminder that espionage clusters can ship professional, multi-family RAT kits while still entering through familiar phishing. Hash coverage buys speed today. Entity-centric triage and durable post-phishing hunts keep the same intrusion set visible after the next packaging change.