HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

SilkParasite Spear‑Phishing Campaign Deploys RATs to Central Asian Government Organizations

SilkParasite, a Chinese‑nexus APT group, used spear‑phishing emails with malicious Office macros to install remote‑access trojans across Central Asian government agencies. The episode highlights the need for SOC 2‑aligned access‑control monitoring and security‑awareness programs to maintain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
darkreading.com

SilkParasite Spear‑Phishing Campaign Deploys RATs to Central Asian Organizations

What Happened – A Chinese‑nexus APT group, tracked as SilkParasite and linked to the FamousSparrow family, launched a spear‑phishing operation targeting government‑affiliated entities across Central Asia. The emails carried malicious attachments that, once opened, installed remote‑access trojans (RATs) capable of full system control and data exfiltration.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a classic credential‑compromise scenario that SOC 2 / CC 3.1 (Logical Access) controls are designed to prevent and evidence.
  • Continuous monitoring of access‑control logs and documented security‑awareness training provide the audit‑ready evidence needed to demonstrate due diligence after a phishing‑driven breach.

Who Is Affected – Primarily government and public‑sector agencies in Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, and Uzbekistan; ancillary private‑sector partners that handle state data are also at risk.

Recommended Actions

  • Map the phishing incident to SOC 2 CC 3.1 controls, verify MFA enforcement, and collect log evidence for audit readiness.
  • Conduct a targeted security‑awareness refresher for all users handling sensitive government data, and validate that phishing‑simulation metrics are captured as continuous compliance evidence.

Source: Dark Reading – SilkParasite Threatens Central Asian Orgs With Flurry of RATs

Technical Notes – The campaign used weaponized Microsoft Office documents exploiting CVE‑2024‑2180 (Office Macro Execution) to drop the “SilkRAT” payload. The RAT communicates over HTTPS, uses encrypted C2 channels, and can exfiltrate files, credentials, and keylogging data.

📰 Original Source
https://www.darkreading.com/threat-intelligence/silkparasite-central-asian-orgs-flurry-rats

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →