Red silk
Image: Ivan Rudoy / Unsplash

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Five previously undocumented strains of malware are being used in attacks on government bodies across Central Asia, threat researchers discovered.

The espionage campaign, known as “SilkParasite,” was allegedly launched by military-grade hackers based in China who used artificial intelligence at various points throughout the malware development process.

Cybersecurity company Bitdefender released a report about the campaign this week, noting that their investigation began with a suspicious infection at an government institution related to the economy in an unnamed Central Asian country. 

Months of forensic investigations and threat hunting uncovered seven malware families and an operation that had been running for nearly one year. 

Bitdefender found malicious documents that were made to look relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia and Kazakhstan — with several impersonating ministries. 

The company theorized that Russia’s declining influence in Central Asia has opened a vacuum that China has been filling economically, prompting the country to spy on the economic arms of governments in the region. 

Bitdefender tied the campaign to China based on links between at least one malware strain and another China-based espionage group. Several of the IP addresses used in the campaign were tied to Chinese telecommunications companies. Over the last year, Bitdefender has tracked two other campaigns with a China nexus targeting Europe and South Asia, including a recent string of incidents aimed at the South Caucasus.

The hackers gained initial access through malicious Microsoft Office documents, typically delivered through spearphishing emails. The lure documents were packaged in archives to get around email-gateway scanning. 

Bitdefender found 65 infections, most of which were in the Asia region, involving DriveSilkRAT — the most widely used of the seven malware strains.

DriveSilkRAT stood out to Bitdefender because it does not talk to a dedicated command and control server like most malware. Instead, it is linked to a shared Google Drive folder — which the threat actors use because network monitors see as ordinary Google Drive traffic that is subject to less scrutiny in most corporate environments. 

AI development

One notable aspect of the SilkParasite campaign was the use of artificial intelligence.

Bitdefender found that two of the email lures were generated by AI and saw other evidence pointing to the use of AI in the development of the malware strains, five of which had not been seen before. 

The company said the campaign is an “example of professional espionage tooling optimized to limit volume: minimum footprint, dynamic in-memory execution, and code deliberately built not to resemble previous malware families.”

“APT-grade malware like this remains firmly the work of human professionals,” they said. “SilkParasite is primarily assisted: capable humans do the engineering and lean on AI to move faster, leaving behind a few tells but none of the degradation.”

Several of the placeholders left in the code of the malware tipped off the use of AI in the development process and showed that even sophisticated state-backed actors are conducting AI-assisted coding.

Capable threat actors are going to “adopt AI slowly and selectively, folding it into professional workflows where it helps and keeping it away from the places where machine-made mediocrity would give the operation away,” Bitdefender explained. 

After years of warnings, AI’s introduction into the cyber threat space appears to be taking form. On Wednesday, the National Security Agency released an urgent warning that unnamed threat actors are using AI-generated exploit scripts to target critical industrial technology that would enable dangerous real world attacks.

The warning came one week after another company claimed it saw an automated cyberattack against the government of Taiwan. 

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.