SilkParasite RAT toolkit activity
Malware Activity
Summary
Hide ▲
Show ▼
SilkParasite's RAT toolkit now includes seven families, with five previously undocumented implants that broaden its espionage capability and reduce detection exposure. The stack combines DLL sideloading, plugin-based modularity, and multiple covert C2 channels to keep operations flexible across victims. One implant uses Google Drive for tasking, while another relies on HTTP Cookie / ETag headers, underscoring a low-footprint design built for stealthy government-targeting espionage.
Related Happenings
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
Campaign
H score26
First: 19.08.2026 16:12
Last: 19.08.2026 16:12
Sources 1
How related:
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
About this happening:
The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
SilkParasite Central Asia government spear-phishing and DLL-sideloading campaign
CampaignHow related: A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
About this happening: The SilkParasite campaign is targeting government bodies in Central Asia with spear-phishing and DLL-sideloading intrusion chains, increasing the risk of stealthy...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityAbout this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
Latest development: 26.08.2026 18:35
Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Timeline
-
19.08.2026 16:12 2 articles · 13d ago
SilkParasite RAT toolkit activity
Initial DisclosureSilkParasite emerged as a modular espionage toolkit with multiple RAT families and covert delivery paths. The early cluster already showed DLL sideloading, spear-phishing, and stealth-oriented command-and-control design.
Show sources
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs — thehackernews.com — 19.08.2026 16:12
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs — thehackernews.com — 19.08.2026 16:12