Cybersecurity & Tech

China's AI-Enabled APT Operations Are Getting Interesting

Tom Uren
Friday, August 28, 2026, 8:00 AM
The latest edition of the Seriously Risky Business cybersecurity newsletter, now on Lawfare.
The Former National Congress of the Communist Party of China (Dong Fang for VOA China, https://tinyurl.com/mteyzmnw. Public Domain.)

China's AI-Enabled APT Operations Are Getting Interesting

A new report describes how a Chinese cyberespionage outfit is using artificial intelligence (AI) to beef up its malware arsenal. If this is a sign of things to come, clustering threat actor behavior together for attribution purposes is about to get a lot harder.

The Bitdefender report, released last week, describes seven remote access tool (RAT) families. Remote access tools allow users to access devices despite not having physical access to the computer or laptop. All seven were created by a single cyberespionage actor Bitdefender called SilkParasite, and five were previously undocumented. The report authors have medium confidence that SilkParasite is, ahem, a "China-nexus actor" targeting governments across Central Asia including Uzbekistan, Turkmenistan, and Kazakhstan.

Back in November, we wrote about what looked like an experiment to see how AI-assisted hacking could support China's Ministry of State Security. The approach those threat actors took at the time was to build an attack framework and let Claude do the hacking. It was error-prone and noisy, but sometimes successful.

SilkParasite, by contrast, is not using AI for yolo hacking. It is using it to support cyberespionage programs where important goals include operating stealthily and not getting caught.

According to Bitdefender, SilkParasite "develops, tests, debugs, and iterates its own tooling, maintains a structured build and deployment workflow, and regularly rotates infrastructure, encryption material, payload names, and persistence artifacts between deployments."

Rotating its infrastructure and indicators of compromise between deployments makes it harder to detect and link its activities together.

SilkParasite also uses a variety of programming languages and command-and-control (C2) protocols. Its seven different RATs are written in different languages including .Net, C++, Go, or JavaScript. C2 occurs by abusing Google Drive and internet communication protocols including HTML, HTTP, TCP, DNS, and TCP.

Its malware also typically uses a modular plug-in architecture where additional functionality is deployed only when it is needed. This means initial implants are relatively small and plugins are used to provide capabilities for clipboard monitoring, keylogging, file management, or interactive shell access. This limits the exposure of the entire toolset during any single deployment. It also allows SilkParasite to update or replace individual components without having to change the entire implant. And it minimizes the amount it writes to disk, typically only the files required to get its malware up and running.

For victim organizations, these measures make forensic analysis more complicated. Complete remediation is also more difficult once a particular implant is detected.

To us, all the behaviors above are the hallmarks of a professional cyberespionage outfit. Of course, doing all of this in a disciplined way is a lot of work, and Bitdefender has evidence SilkParasite is using AI to help it deliver this complex engineering.

SilkParasite's malware contains indicators of AI-assisted development, such as leftover test functions and placeholder encryption keys. Intriguingly, implants that Bitdefender dubbed GoginRAT and NomadRAT share a high-level architecture even though they are written in Go and C++, respectively, and use different C2 protocols and code structure.

Bitdefender suspects that the same high-level specification document was independently implemented twice with AI assistance. Bitdefender concedes that this structural similarity is not conclusive evidence but notes that it is the "kind of thing an AI-assisted workflow makes easy."

This is the first example we've seen where the evidence tells a compelling story of a competent cyberespionage actor incorporating AI into its work practices. SilkParasite is taking the same, disciplined approach to malware development and doing more of it. It’s creating more malware families to build redundancy, make attribution and discovery harder, and reduce the risk of compromise from any single exposure.

Bitdefender has done a good job describing SilkParasite's malware families and has published Indicators of Compromise. That kind of exposure would once have set the group back significantly. Now that they've figured out how to use AI to speed up their development work, they'll be back and better than ever relatively quickly.

Then the discovery, attribution, and publication merry-go-round can start all over again.

U.S. Throws the Kitchen Sink at Iranian Hackers

In the wake of cyberattacks on its water infrastructure, the U.S. is trying a new trick in its sanctions against Iranian hackers: pointing out they're also hacking Iran's own companies.

Last week, the U.S. government launched Operation Economic Outcast, an "unprecedented campaign" targeting the Iranian government. It included more sanctions, including against six hackers working on behalf of Iran's Ministry of Intelligence and Security (MOIS).

Three of the hackers are hands-on-keyboard operators responsible for wide-ranging campaigns targeting American organizations including from critical infrastructure and government. The sanctions also named two leaders of the hacking group.

So far, so normal.

What is new here is that buried in the middle of its 5,300-word press release, the Treasury Department calls out two of the hackers for targeting Iranian interests:

The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS. This has driven some of the group to target Iranian companies. In spring 2025, [one of the group's leaders] Mojtaba Ghal'eh-Kuhi and [hands-on hacker] Saber Shahbazi Balujeh compromised and exfiltrated data from an Iranian telecommunications company.

Hamid Kashfi, a cybersecurity researcher with expertise in Iranian cyberespionage, told Seriously Risky Business that being named in sanctions packages previously had been viewed as a "stamp of approval" within Iran.

"Some people have been rewarded for that internally," he said.

Kashfi thought that "airing their dirty laundry" and revealing that some individuals had been hacking Iranian companies could cause internal conflict and friction. He said that although hacking for personal gain was a "recognizable pattern" among some Iranian actors, it was still likely that this incident was news to their employers.

So the information itself could plausibly result in repercussions for some of Iran's hackers and therefore impacts on the effectiveness of Iran's cyber operations. We are left wondering, however, about the way it was published: buried in the middle of a Treasury press release, without any corroborating information.

Is the claim legit? How would the Treasury know? Why is it buried in the middle of a press release? Why should any Iranian MOIS official or hacker take it seriously?

This reminds us of how the FBI and the KGB attempted to sow discord within target organizations. In these historical examples, the agencies planted fraudulent documents or spread false rumors to degrade trust from within an organization. Although we don't agree with the goals of the operations we've linked to, the agencies running them at least came up with deliberate plans for how and where to disseminate their disinformation. They didn't just bury a claim in a presser.

But whatever, it's fun to see the U.S. government come up with a new way to potentially make things awkward around the office for hackers working for the Iranian state.

AI Is Too Cool to Be Critical

A new report calling for the U.S. government to designate AI as critical infrastructure makes sense, but we also don't think the government should bother.

The report, produced by the nonprofit Americans for Responsible Innovation and first covered by CyberScoop, makes the argument that frontier AI models and associated infrastructure are already a critical infrastructure sector.

They're probably right, but one purpose of a critical infrastructure designation is to prioritize government resources, and the AI sector is certainly not sitting in the corner being ignored by the government. When frontier labs complained about Chinese distillation, the government response was rapid: Intellectual property theft must be thwarted!

It's clear the government's attention is already focused on AI, so designating it critical infrastructure, at least for now, would simply be more paperwork for the same resources.

AI should become critical infrastructure when it is boring. Until then, don't bother.

Three Reasons to Be Cheerful This Week:

  1. More granular permissions for Windows 11: Microsoft is testing per-app permission for camera, location, and microphone access in new preview builds of Windows 11. Currently, these permissions are granted in a single device-wide setting.
  2. Interpol tackles West African organized crime: Interpol has announced that eight-month-long Operation Jackal IV has led to 58 arrests and the identification of 263 suspects. A total of 22 countries participated in the operation.
  3. Water-sector organization beats CISA red team: A Cybersecurity and Infrastructure Security Agency (CISA) red team report says that an organization in the water and wastewater sector was able to detect and respond to a simulated cyber intrusion attempt. So there will be some water-sector organizations that are well placed to respond to attempted Iranian attacks.

Risky Biz Talks

In our latest "Between Two Nerds" discussion, Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack.

From Risky Bulletin:

Russia starts blocking DoH and DoT: Russian internet users started reporting issues with connecting to DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) servers, suggesting the government might have cracked down on the two protocols.

Both DoH and DoT are privacy-centric versions of the DNS protocol that hide a user's DNS queries and intended destination from internet service providers and threat actors on the wire.

Both protocols have seen increased usage in Russia. They are typically used together with a VPN client as a way to bypass the Kremlin's ever-increasing and overbearing internet censorship, and access Western websites.

[more on Risky Bulletin]

Expired cards can be used for new transactions: A team of academics from the University of Massachusetts Amherst have developed an attack that can revive old expired contactless cards to perform new (illegal) transactions.

The attack exploits the fact that NFC card data is not fully encrypted when making a payment and some parameters can be modified without breaking the card's digital hash/signature.

The researchers created a rig that intercepts transaction data through an NFC Man-in-the-Middle attack, updates the expiration date, and relays the modified payment to a Point-of-Sale (POS) terminal.

[more on Risky Bulletin]

Academics find source code overlaps between Geedge and China's Great Firewall: A team of American academics have found source code overlaps between the products of a Chinese tech company and the country's Great Firewall traffic filtering and censorship system.

According to research presented at this year's USENIX security conference, the Chinese government is using the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.

Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.

[more on Risky Bulletin]

 


Tom Uren writes Seriously Risky Business, a big-picture, policy-focused cyber security newsletter. He also co-hosts the Seriously Risky Business and Between Two Nerds podcasts that appear on the Risky Business News feed. He was formerly a Senior Analyst in the Australian Strategic Policy Institute's (ASPI) Cyber Policy Centre where he contributed to various projects including on offensive cyber capabilities, information operations, the Huawei debate in Australia and end-to-end encryption.
}

Subscribe to Lawfare