# Five New RATs, One Shadow: Inside the SilkParasite Espionage Campaign Hitting Central Asia


Central Asian governments are quiet targets — geopolitically landlocked between spheres of Russian and Chinese influence, often underresourced on defensive security, and rarely the subject of Western threat intelligence coverage. That combination makes them a persistent magnet for espionage operations that fly under the radar for years. SilkParasite is the latest example, and it's more technically ambitious than its obscurity might suggest.


Researchers have now documented a previously unreported intrusion campaign targeting government entities across Central Asia. Seven remote access tool families are in play. Five of them — DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT — have never been seen before. That level of custom tooling investment doesn't happen by accident, and it doesn't happen cheap.


## What Five Undocumented RATs Actually Mean


Nation-state operations typically cycle through one or two custom tools, padding out the kit with modified open-source or leaked commercial malware. Five brand-new RAT families in a single campaign is unusual enough to anchor everything else you need to know about this threat actor: they are well-resourced, deliberate, and almost certainly operating on a multi-year timeline.


The naming conventions the researchers assigned offer some technical signals. DriveSilkRAT almost certainly uses Google Drive or another cloud storage service as its command-and-control channel — a technique that blends C2 traffic into legitimate HTTPS activity and defeats network-layer detection tools that can't inspect encrypted cloud storage traffic. CookiETagRAT is more interesting: ETags are HTTP headers used for web caching that very few security monitoring tools inspect or log. Using them as a covert signaling mechanism is clever because it exploits a blind spot in most enterprise SIEM deployments.


GoginRAT points to Go-based development — possibly using the Gin web framework — which has become increasingly common in nation-state tooling because Go binaries are self-contained, cross-compilable, and harder to reverse-engineer than Python or PowerShell payloads. NodeEdgeRAT suggests either a Node.js-based implant or something weaponizing Microsoft Edge's runtime. NomadRAT is the wildcard; without fuller technical reporting, it's unclear whether "nomad" refers to lateral movement behavior, cross-platform capability, or something about how it persists.


## The Central Asian Theater


The geographic targeting here matters as much as the technical details. The five Central Asian republics — Kazakhstan, Uzbekistan, Tajikistan, Kyrgyzstan, and Turkmenistan — sit at the intersection of competing strategic interests. Russia maintains legacy military and intelligence infrastructure across the region. China's Belt and Road Initiative has driven deep economic penetration. The United States and EU have made periodic democratic partnership overtures, particularly after the 2022 Russian invasion of Ukraine accelerated some regional hedging.


Government networks in this region often run aging infrastructure, underfunded security teams, and a patchwork of Russian-legacy and Chinese-supplied networking equipment — neither of which tends to ship with robust logging or endpoint detection capabilities. For an espionage actor, it's favorable terrain.


The "Silk" in SilkParasite is a pointed reference. The Silk Road ran through Central Asia, and the naming pattern — DriveSilkRAT, SilkParasite — suggests the operator or the researchers naming the campaign wanted to anchor the geographic context directly. China-nexus attribution is a reasonable hypothesis given the BRI footprint and the region's strategic value to Beijing, but Russian-linked actors have also maintained persistent presence targeting Central Asian government ministries, particularly around CSTO decision-making and energy infrastructure.


## Seven Tools, One Question: How Long Has This Been Running?


First observed in late 2025, SilkParasite's actual dwell time is almost certainly longer. Five novel RAT families don't emerge fully formed — they represent iterative development, testing, and operational refinement that typically spans 12 to 24 months before deployment. The version of these tools that researchers found is probably not their first.


This matters for defenders trying to scope an incident. If SilkParasite has been active in some form since 2024 or earlier, government networks that show indicators of compromise from the documented toolset may have substantially longer periods of undetected access than the discovery timeline implies.


---


## HackWire Analysis


The thing other coverage will likely miss here is the infrastructure economics argument. Running seven RAT families — maintaining them, updating them to evade detection, training operators, managing C2 infrastructure across what is presumably multiple target environments — requires a real budget and a real team. This isn't a small group of contractors running an opportunistic campaign. SilkParasite looks more like a program than an operation.


Compare this to something like APT41 or Turla, both of which maintain extensive custom tooling portfolios developed over years. The CookiETag technique in particular places this actor in sophisticated company — ETag-based C2 has been discussed in academic and threat research contexts as a detection-evasion primitive, but it rarely shows up in actual documented campaigns. When it does, it marks someone who has read the literature and built accordingly.


For defenders in the region — which is a small audience, but an important one — the immediate priority is checking whether Google Drive traffic from internal endpoints shows unusual patterns. Drive C2 is identifiable if you're looking for it: unusual file access patterns, GDrive connections from systems that have no business reason to authenticate to cloud storage, or high-frequency low-volume traffic to Drive APIs. Standard EDR won't catch DriveSilkRAT without cloud traffic inspection in the loop.


More broadly, this campaign confirms a pattern that's been building since 2022: the geopolitical turbulence around Russia's war in Ukraine pushed Central Asian governments toward more active fence-sitting, and that increased strategic importance has made their government networks higher-priority collection targets for multiple adversaries simultaneously. Defense budgets in the region have not kept pace.


The five new tools will eventually get signatures. The question is how long SilkParasite ran before those signatures existed.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)