Threat Intelligence

New Espionage Campaign 'SilkParasite' Deploys Five Undocumented Hacking Tools

The Hacker News · 19 Aug 2026
Key Takeaway Ensure your business monitors for unusual network activity and keeps endpoint security tools updated, since newly developed malware often evades signature-based detection.

Security researchers have uncovered a previously unreported cyber espionage campaign, dubbed SilkParasite, that is actively targeting government organisations in Central Asia. The operation, first identified in late 2025, uses seven different remote access tool (RAT) families to infiltrate and control compromised systems, including five entirely new malware strains never before documented by security researchers: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.

While the current targets appear to be government bodies rather than private businesses, campaigns like this are a reminder that threat actors are constantly developing new, undetected tools to evade traditional security defences. Espionage-focused groups often refine their techniques on government targets before those same tools and methods trickle down to be used against private sector organisations, including small and medium businesses that may hold valuable data or serve as a stepping stone to larger partners.

Although details remain limited as researchers continue to analyse the campaign, the emergence of five brand-new RAT families in a single operation highlights the scale of investment threat actors are putting into custom malware development. Businesses should treat this as a signal to review their detection capabilities, particularly around unusual outbound network connections that can indicate a RAT has been installed.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.