Chinese-Linked Hacking Group Targets Central Asian Organisations with Remote Access Trojans
Security researchers have identified a spear-phishing campaign, attributed to a Chinese-nexus group called SilkParasite, targeting organisations across Central Asia. The group is believed to be linked to FamousSparrow, a known advanced persistent threat (APT) actor, and is using phishing emails to deliver a range of remote access trojans (RATs) to compromised systems.
The campaign offers insight into the broader geopolitical, technical, and strategic activities of Chinese state-linked APT groups, suggesting these operations are part of a wider pattern of cyber-espionage efforts extending beyond China's immediate borders. While the current campaign is focused on Central Asian organisations, the tactics, techniques, and tools used by such groups often evolve and spread to other regions over time.
Australian small and medium businesses may not be direct targets of this specific campaign, but the use of spear-phishing as an entry point remains a common tactic used by many threat actors worldwide, including those targeting smaller organisations as stepping stones to larger supply chains.