Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel so activity looks like normal cloud traffic. Researchers also found signs that some email lures and parts of the tooling were AI-assisted.
How the attack worked
Bitdefender investigated a suspicious infection at a government institution tied to the economy in an unnamed Central Asian country. The investigation uncovered a broader espionage campaign, dubbed SilkParasite, that had been running for nearly one year and involved seven distinct malware families. Initial access came through spearphishing emails carrying malicious Microsoft Office documents, frequently packaged inside archives to slip past email-gateway scanning.
Once a document was opened, the most widely used malware strain, DriveSilkRAT, avoided a traditional command-and-control server. Instead, it communicated through a shared Google Drive folder, which let its traffic blend in as ordinary cloud activity that receives less scrutiny in most corporate environments.
Why it succeeded
The lure documents were crafted to look relevant to government agencies across several countries, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia and Kazakhstan, with several impersonating ministries directly. This context-specific tailoring made the documents more believable to recipients working in economic and government roles. Using a well-known cloud service like Google Drive for command and control also worked against typical network monitoring, since analysts and tools tend to treat traffic to major cloud platforms as low risk.
Bitdefender also found that at least two of the email lures were generated by AI, alongside other indicators of AI-assisted malware development. This suggests the operators combined skilled human engineering with AI tools to produce convincing content more quickly.
What to watch for
- Unexpected archive attachments containing Office documents, especially those claiming to originate from a ministry or government body
- Messages that appear closely tailored to your specific agency, role, or country context
- Unusual or unexplained Google Drive activity following the opening of an email attachment
- Cloud service traffic patterns that do not match a user's normal behavior
Building resistance
Organizations in government and public sector roles should treat archived attachments as inherently higher risk, particularly when they carry Office documents from unfamiliar or unverified senders. Staff should be encouraged to question documents that seem unusually relevant to their specific role or agency, since this kind of tailoring is a deliberate technique to build trust. Security teams should also avoid assuming that traffic to well-known cloud services like Google Drive is automatically safe, and should monitor for anomalous patterns even within trusted platforms. Finally, as AI-assisted phishing content becomes more common, awareness training should emphasize that polished, error-free lures are no longer a reliable sign of legitimacy.
Key findings
- Bitdefender investigated a “suspicious infection” at “a government institution related to the economy” in an unnamed Central Asian country.
- Researchers identified “seven malware families” and said the operation had been running “for nearly one year.”
- Initial access was achieved via spearphishing emails delivering “malicious Microsoft Office documents,” often “packaged in archives to get around email-gateway scanning.”
- Lure documents were crafted to look relevant to government agencies across multiple countries and included “several impersonating ministries.”
- DriveSilkRAT used a shared Google Drive folder for communications instead of a traditional command-and-control server, to blend in as normal Google Drive traffic.
- Bitdefender found that “two of the email lures were generated by AI” and observed additional indicators of AI-assisted malware development.
Who’s being targeted
- Commonly targeted roles: Government employees, Executive leadership, Finance/Economics ministry staff, Administrative assistants, IT and Security Operations (SOC).
- Affected industries: Government (economic/ministries and agencies), Public sector institutions.
- Attack channels: email.
- Impersonated: A government ministry (impersonated), Google Drive traffic (appears legitimate).
Red flags to watch for
- Unexpected archive attachment used to deliver a document
- Sender claims to be a ministry/official body but message arrives via an untrusted or unusual route
- Document topic is designed to look “relevant” to the recipient’s government work
- Unusual Google Drive activity following the opening of a document attachment
- Cloud service traffic that does not match the user’s normal pattern
- Security tools may treat common cloud services with “less scrutiny”
Frequently asked questions
What is SilkParasite?
SilkParasite is the name given to a China-linked espionage campaign, identified by Bitdefender, that targeted government institutions in Central Asia using spearphishing emails with malicious Microsoft Office documents.
How did SilkParasite gain initial access?
Attackers delivered malicious Microsoft Office documents through spearphishing emails, often packaging them inside archives to bypass email-gateway scanning.
Why did SilkParasite use Google Drive?
One malware strain, DriveSilkRAT, communicated through a shared Google Drive folder instead of a traditional command-and-control server, so its traffic blended in with ordinary Google Drive activity that receives less scrutiny in most corporate environments.
Was AI used in this campaign?
Bitdefender found that at least two of the email lures were generated by AI, along with additional signs of AI-assisted malware development.
Read the video transcript
You get an email: a ‘Ministry of Economy’ in Central Asia wants you to review a Microsoft Office document in an attached ZIP file. This is SilkParasite. Bitdefender found seven malware families behind these spearphish docs, some AI-written, hitting ministries across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan. Here’s the twist: after you open the doc, their DriveSilkRAT malware quietly talks to a shared Google Drive folder, so your network just sees ‘normal’ Google Drive traffic. Your move: if you ever get an unexpected archived Office doc claiming to be from a ministry, stop, don’t open it. Report it to security immediately and let them check it.