New Espionage Campaign 'SilkParasite' Deploys Five Undocumented Hacking Tools
Security researchers have uncovered a previously unreported cyber espionage campaign, dubbed SilkParasite, that is actively targeting government organisations in Central Asia. The operation, first identified in late 2025, uses seven different remote access tool (RAT) families to infiltrate and control compromised systems, including five entirely new malware strains never before documented by security researchers: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.
While the current targets appear to be government bodies rather than private businesses, campaigns like this are a reminder that threat actors are constantly developing new, undetected tools to evade traditional security defences. Espionage-focused groups often refine their techniques on government targets before those same tools and methods trickle down to be used against private sector organisations, including small and medium businesses that may hold valuable data or serve as a stepping stone to larger partners.
Although details remain limited as researchers continue to analyse the campaign, the emergence of five brand-new RAT families in a single operation highlights the scale of investment threat actors are putting into custom malware development. Businesses should treat this as a signal to review their detection capabilities, particularly around unusual outbound network connections that can indicate a RAT has been installed.