China Linked Spy Campaign Targets Central Asian Governments With New Malware
A cyber espionage operation dubbed SilkParasite has targeted government organisations across Uzbekistan, Turkmenistan, Tajikistan, Kazakhstan and Kyrgyzstan, with one reported case involving Georgia,...
- A China linked cyber espionage campaign has targeted government organisations across Central Asia using phishing, malicious documents and several previously undocumented malware families. The campaign highlights a growing compliance problem for public institutions and businesses: cyber risk is increasingly tied to geopolitical and data security risk.
A cyber espionage operation dubbed SilkParasite has targeted government organisations across Uzbekistan, Turkmenistan, Tajikistan, Kazakhstan and Kyrgyzstan, with one reported case involving Georgia, according to research reported by Cybersecurity News. The campaign was first detected around October 2025 and appears to have remained active for much of the following year.
Researchers identified five previously undocumented malware families, alongside seven remote access tools used to maintain access to compromised systems. Attackers reportedly relied on government themed documents and spear phishing emails, including password protected RAR archives, to persuade victims to open malicious files.
Separate reporting byThe Record, citing cybersecurity company Bitdefender, said investigators found evidence that AI was used during parts of the malware development process. The operation appeared focused on intelligence gathering rather than indiscriminate disruption.
The attribution to China remains a researcher assessment rather than a publicly established legal finding.
Compliance Analysis
For compliance teams, the significance lies in what attackers were trying to obtain. Government systems contain sensitive information, while businesses increasingly hold commercially valuable data, intellectual property and personal information that can become strategic intelligence.
That makes cybersecurity a governance issue, not simply an IT problem.
The campaign also demonstrates why third-party risk deserves greater attention. A phishing email may exploit a trusted document, software application or external service before reaching the organisation’s own systems.
For regulated businesses, a successful intrusion can trigger obligations involving data protection, incident reporting, operational resilience and regulatory notification.
The use of AI also raises the cost of detection. Faster malware development can mean shorter windows between discovering a vulnerability and exploiting it.
The broader lesson is straightforward: geopolitical risk can become cyber risk, and cyber risk can quickly become compliance risk.



No Comment! Be the first one.