Researchers identified a previously unknown espionage campaign targeting Central Asian government entities. The operation, tracked as SilkParasite, deploys seven remote access trojan families. Five of these tools appear for the first time in public disclosure: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.

The campaign emerged in late 2025. Threat actors behind SilkParasite gain persistent access to victim networks through these RAT families, enabling them to exfiltrate sensitive government data and maintain long-term surveillance capabilities. Each RAT variant demonstrates distinct command-and-control infrastructure and operational characteristics, suggesting a well-resourced threat group with specialized tooling for different attack phases.

The targeting of Central Asian governments indicates a geopolitically motivated operation. State-sponsored actors typically develop diverse RAT portfolios to bypass detection and maintain redundancy if individual tools are discovered or blocked. The five newly documented families suggest SilkParasite operators invested significant development effort before launching operational campaigns.

Organizations in Central Asia face elevated risk from this activity. Network defenders should monitor for indicators of compromise associated with these RAT families, including unusual outbound connections, suspicious scheduled tasks, and registry modifications typical of persistence mechanisms. Government agencies should prioritize endpoint detection and response capabilities to identify command-and-control beaconing and lateral movement attempts.

The discovery of five undocumented RATs in a single campaign underscores how espionage operations often operate undetected for extended periods before public attribution. Threat intelligence sharing between regional governments and private sector partners becomes essential for detection and remediation. Organizations should apply network segmentation to isolate critical systems from compromised networks and implement strong authentication controls on administrative accounts, as RAT operators typically target privileged access to maintain persistence.