SYMBOLCOMMON_NAMEaka. SYNONYMS

SilkParasite  (Back to overview)


SilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications entities in Kyrgyzstan, Uzbekistan and Kazakhstan. Bitdefender assesses a China-nexus with medium confidence and states explicitly that it does not believe the evidence supports attribution to a named group, so this is recorded as an activity cluster rather than as an established actor. Observed tooling spans seven implant families: five named by Bitdefender (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT) plus SpiceRAT, previously reported by Cisco Talos in connection with SneakyChef, and BloodAlchemy, a lineage descended from ShadowPad and Deed RAT. The operators favour DLL sideloading and cloud services as command-and-control channels, and register domains impersonating local hosting providers.


Associated Families

There are currently no families associated with this actor.


References
2026-08-19BitdefenderMartin Zugec
SilkParasite: Tracking a China-Nexus APT Across Central Asia
BloodAlchemy ShadowPad SNAPPYBEE SilkParasite

Credits: MISP Project