Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
SilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications entities in Kyrgyzstan, Uzbekistan and Kazakhstan. Bitdefender assesses a China-nexus with medium confidence and states explicitly that it does not believe the evidence supports attribution to a named group, so this is recorded as an activity cluster rather than as an established actor. Observed tooling spans seven implant families: five named by Bitdefender (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT) plus SpiceRAT, previously reported by Cisco Talos in connection with SneakyChef, and BloodAlchemy, a lineage descended from ShadowPad and Deed RAT. The operators favour DLL sideloading and cloud services as command-and-control channels, and register domains impersonating local hosting providers.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database