Find notable cyber news and cases, enriched with sources, timelines, and signals.

SilkParasite RAT toolkit activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection exposure. The stack combines DLL sideloading, plugin-based modularity, and multiple covert C2 channels to keep operations flexible across victims. One implant uses Google Drive for tasking, while another relies on HTTP Cookie / ETag headers, underscoring a low-footprint design built for stealthy government-targeting espionage.

Related Happenings

SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign

Campaign
H score26 First: 19.08.2026 16:12 Last: 19.08.2026 16:12 Sources 1

How related: A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.

About this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...

Latest development: 26.08.2026 18:35

Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Timeline

  1. 19.08.2026 16:12 2 articles · 13d ago

    SilkParasite RAT toolkit activity

    Initial Disclosure

    SilkParasite emerged as a modular espionage toolkit with multiple RAT families and covert delivery paths. The early cluster already showed DLL sideloading, spear-phishing, and stealth-oriented command-and-control design.

    Show sources