SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported espionage campaign called SilkParasite has been targeting Central Asian government entities using seven RAT families, five of which are newly discovered: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. First identified in late 2025, the intrusion set represents a significant expansion in the threat landscape for the region, introducing multiple previously undocumented remote access capabilities.
The U.S. has indicted Iranian cyber espionage operations while Medusa ransomware has compromised over 500 organizations, highlighting active threats across state-sponsored and criminal landscapes. Attackers are actively exploiting a critical Windows protocol vulnerability, demonstrating how legacy systems remain prime targets for threat actors.
Cybersecurity researchers have attributed a malicious backdoor discovered in compromised Rust packages to North Korean threat actors, connecting it to their historical supply chain attack campaigns. This incident demonstrates continued efforts by the nation-state group to infiltrate software dependencies and gain access to downstream users and organizations.
Suspected Russian cyber espionage groups UNC6293, UNC7005, and UNC5976 are exploiting legitimate authentication mechanisms including Google OAuth and WhatsApp linking to compromise accounts of individuals in academia, aerospace, defense, government, and think tanks across Europe and the United States. The threat actors demonstrate persistent and adaptive tactics in targeting these high-value sectors, leveraging trusted services to bypass conventional security measures and gain unauthorized access to sensitive accounts.