SilkParasite Hits Central Asia via Phish Docs

The Record · High sophistication
Last updated August 21, 2026

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel so activity looks like normal cloud traffic. Researchers also found signs that some email lures and parts of the tooling were AI-assisted.

How the attack worked

Bitdefender investigated a suspicious infection at a government institution tied to the economy in an unnamed Central Asian country. The investigation uncovered a broader espionage campaign, dubbed SilkParasite, that had been running for nearly one year and involved seven distinct malware families. Initial access came through spearphishing emails carrying malicious Microsoft Office documents, frequently packaged inside archives to slip past email-gateway scanning.

Once a document was opened, the most widely used malware strain, DriveSilkRAT, avoided a traditional command-and-control server. Instead, it communicated through a shared Google Drive folder, which let its traffic blend in as ordinary cloud activity that receives less scrutiny in most corporate environments.

Why it succeeded

The lure documents were crafted to look relevant to government agencies across several countries, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia and Kazakhstan, with several impersonating ministries directly. This context-specific tailoring made the documents more believable to recipients working in economic and government roles. Using a well-known cloud service like Google Drive for command and control also worked against typical network monitoring, since analysts and tools tend to treat traffic to major cloud platforms as low risk.

Bitdefender also found that at least two of the email lures were generated by AI, alongside other indicators of AI-assisted malware development. This suggests the operators combined skilled human engineering with AI tools to produce convincing content more quickly.

What to watch for

  • Unexpected archive attachments containing Office documents, especially those claiming to originate from a ministry or government body
  • Messages that appear closely tailored to your specific agency, role, or country context
  • Unusual or unexplained Google Drive activity following the opening of an email attachment
  • Cloud service traffic patterns that do not match a user's normal behavior

Building resistance

Organizations in government and public sector roles should treat archived attachments as inherently higher risk, particularly when they carry Office documents from unfamiliar or unverified senders. Staff should be encouraged to question documents that seem unusually relevant to their specific role or agency, since this kind of tailoring is a deliberate technique to build trust. Security teams should also avoid assuming that traffic to well-known cloud services like Google Drive is automatically safe, and should monitor for anomalous patterns even within trusted platforms. Finally, as AI-assisted phishing content becomes more common, awareness training should emphasize that polished, error-free lures are no longer a reliable sign of legitimacy.

Key findings

  • Bitdefender investigated a “suspicious infection” at “a government institution related to the economy” in an unnamed Central Asian country.
  • Researchers identified “seven malware families” and said the operation had been running “for nearly one year.”
  • Initial access was achieved via spearphishing emails delivering “malicious Microsoft Office documents,” often “packaged in archives to get around email-gateway scanning.”
  • Lure documents were crafted to look relevant to government agencies across multiple countries and included “several impersonating ministries.”
  • DriveSilkRAT used a shared Google Drive folder for communications instead of a traditional command-and-control server, to blend in as normal Google Drive traffic.
  • Bitdefender found that “two of the email lures were generated by AI” and observed additional indicators of AI-assisted malware development.

Who’s being targeted

  • Commonly targeted roles: Government employees, Executive leadership, Finance/Economics ministry staff, Administrative assistants, IT and Security Operations (SOC).
  • Affected industries: Government (economic/ministries and agencies), Public sector institutions.
  • Attack channels: email.
  • Impersonated: A government ministry (impersonated), Google Drive traffic (appears legitimate).

Red flags to watch for

  • Unexpected archive attachment used to deliver a document
  • Sender claims to be a ministry/official body but message arrives via an untrusted or unusual route
  • Document topic is designed to look “relevant” to the recipient’s government work
  • Unusual Google Drive activity following the opening of a document attachment
  • Cloud service traffic that does not match the user’s normal pattern
  • Security tools may treat common cloud services with “less scrutiny”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is SilkParasite?

SilkParasite is the name given to a China-linked espionage campaign, identified by Bitdefender, that targeted government institutions in Central Asia using spearphishing emails with malicious Microsoft Office documents.

How did SilkParasite gain initial access?

Attackers delivered malicious Microsoft Office documents through spearphishing emails, often packaging them inside archives to bypass email-gateway scanning.

Why did SilkParasite use Google Drive?

One malware strain, DriveSilkRAT, communicated through a shared Google Drive folder instead of a traditional command-and-control server, so its traffic blended in with ordinary Google Drive activity that receives less scrutiny in most corporate environments.

Was AI used in this campaign?

Bitdefender found that at least two of the email lures were generated by AI, along with additional signs of AI-assisted malware development.

Read the video transcript

You get an email: a ‘Ministry of Economy’ in Central Asia wants you to review a Microsoft Office document in an attached ZIP file. This is SilkParasite. Bitdefender found seven malware families behind these spearphish docs, some AI-written, hitting ministries across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. Here’s the twist: after you open the doc, their DriveSilkRAT malware quietly talks to a shared Google Drive folder, so your network just sees ‘normal’ Google Drive traffic. Your move: if you ever get an unexpected archived Office doc claiming to be from a ministry, stop, don’t open it. Report it to security immediately and let them check it.

Categories

Similar attacks

Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
SilkParasite Uses Ministry-Themed Phishing to Drop RATs

SilkParasite Uses Ministry-Themed Phishing to Drop RATs

Researchers reported a real espionage campaign (“SilkParasite”) targeting Central Asian government bodies using spear‑phishing emails. The attack uses password‑protected RAR files containing malicious Microsoft Office documents; when opened, macros trigger a DLL sideloading chain to install remote…

August 19, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Fake Claude Download Used in JadeProx Attacks

Fake Claude Download Used in JadeProx Attacks

Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including spear-phishing and a fake software download site. One campaign impersonated Anthropic’s Claude using a lookalike domain to deliver a malicious…

July 23, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026