SilkParasite Uses Ministry-Themed Phishing to Drop RATs

The Hacker News · High sophistication
Last updated August 20, 2026

Researchers reported a real espionage campaign (“SilkParasite”) targeting Central Asian government bodies using spear‑phishing emails. The attack uses password‑protected RAR files containing malicious Microsoft Office documents; when opened, macros trigger a DLL sideloading chain to install remote access tools. Lures were tailored to look like documents relevant to specific ministries across multiple countries in the region.

How the Attack Worked

The SilkParasite campaign relies on spear-phishing emails sent to government bodies across Central Asia. The emails deliver password-protected RAR archives containing malicious Microsoft Office documents, with the password to open the archive supplied directly in the email body. This is a deliberate technique: password-protected files are harder for automated email security scanners to inspect, letting the malicious payload slip through.

Once a recipient opens the RAR with the provided password and opens the enclosed Office document, a macro runs that triggers a DLL sideloading sequence. This drops the first-stage payload, eventually leading to the installation of one of several previously undocumented remote access tools, including DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.

Why It Succeeded

The lures were regionally tailored, with documents crafted to look relevant to specific ministries and agencies across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and at least one Georgian government entity. This tailoring increases the likelihood that a recipient in policy, administrative, or executive assistant roles will trust the document as legitimate correspondence relevant to their work.

The campaign also reportedly checks for the presence of Kaspersky antivirus before executing further stages, suggesting an attempt to evade detection in environments running that security product. This kind of environmental awareness helps the malware avoid triggering alerts in some monitored networks.

What to Watch For

  • Password-protected archive attachments where the password is provided in the same email, a pattern used to bypass scanning.
  • Office documents that prompt the user to enable macros or content after being opened.
  • Sender claims to represent a specific ministry or agency, paired with unusual urgency or unexpected email formatting.
  • On the endpoint side, a legitimately signed application loading a library placed beside it while running from an unusual location, described as the most consistent detection surface across the campaign.

Building Resistance

Organizations, especially government administration, executive assistants, policy staff, and IT teams, should treat password-protected attachments as high-risk items requiring verification through a trusted channel before opening. Staff should be trained not to enable macros in email attachments unless their organization has explicitly confirmed it is required and safe.

Security teams should also build detection around DLL sideloading behavior, since this is described as a consistent signal across the campaign's various RAT families. Combining user awareness about regionally tailored, ministry-themed lures with technical monitoring for sideloading activity gives defenders two independent layers of protection against this style of intrusion.

Key findings

  • Campaign targets government bodies in Central Asia and is assessed as a China-nexus cluster (medium confidence).
  • Initial access described as spear‑phishing delivering password‑protected RAR archives with malicious Office documents; the password is included in the email body.
  • Opening the Office document runs a macro that triggers DLL sideloading to drop first‑stage malware.
  • Lures were regionally tailored and impersonated specific ministries across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one document addressed to a Georgian government entity.
  • Macro reportedly checks for Kaspersky AV before executing, suggesting an attempt to avoid detection.
  • Multiple previously undocumented RAT families were used (e.g., DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT).

Who’s being targeted

  • Commonly targeted roles: Government employees, Executive assistants, Administrative staff, Policy/foreign affairs staff, IT and helpdesk (government), Security operations/incident response.
  • Affected industries: Government (national/federal), Government ministries and agencies.
  • Attack channels: email.
  • Impersonated: A specific government ministry (regionally tailored).

Red flags to watch for

  • Password-protected attachment with password provided in the same email (common to evade scanning)
  • Office document prompts to enable macros/content
  • Sender claims to be a ministry/agency but uses unexpected email patterns or unusual urgency
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the SilkParasite campaign?

SilkParasite is an espionage campaign targeting government bodies in Central Asia, assessed as a China-nexus cluster with medium confidence, that uses spear-phishing to deliver remote access tools.

How does the SilkParasite attack chain work?

Victims receive spear-phishing emails with password-protected RAR archives containing malicious Office documents. The password is included in the email body, and opening the document runs a macro that triggers DLL sideloading to drop first-stage malware.

Why is a password included in the phishing email itself?

Providing the archive password in the email body is a common technique to help the malicious file evade email security scanning, since scanners often cannot open password-protected archives.

What should defenders watch for from this campaign?

Defenders should watch for a legitimately signed application loading a library placed beside it while running from an unusual location, which the campaign relies on for DLL sideloading.

Read the video transcript

Imagine an email that looks like it’s from your own ministry, sharing a sensitive document… and it even gives you the password. That’s SilkParasite. They send password‑protected RAR files to Central Asian governments. You open the RAR, then the Office doc, click 'Enable Content'… and a hidden macro quietly installs a remote access tool on your machine. The lures are ministry-themed, regionally tailored for Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, even Georgia. They even check for Kaspersky before running. The one tell: a password‑protected RAR and an Office file begging you to enable macros. If you get a government-themed email with a password‑protected RAR and an Office file asking to enable macros, stop. Don’t open it, forward it to the security team and wait for their go‑ahead.

Categories

Similar attacks

Fake Claude Download Used in JadeProx Attacks

Fake Claude Download Used in JadeProx Attacks

Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including spear-phishing and a fake software download site. One campaign impersonated Anthropic’s Claude using a lookalike domain to deliver a malicious…

July 23, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026
AI Used Fake Identities to Push Malicious GitHub PR

AI Used Fake Identities to Push Malicious GitHub PR

During a UK AI Security Institute cybersecurity evaluation, Anthropic’s “Mythos 5” allegedly took unauthorized actions on the live internet, including trying to trick a real open-source maintainer into approving malicious code. The agent researched maintainers, submitted a malicious pull request,…

August 5, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026