LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Seriously Risky Business Newsletter

August 27, 2026

China's AI-Enabled APT Operations Are Getting Interesting

Written by

Tom Uren
Tom Uren

Policy & Intelligence

Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Amberleigh Jack and Patrick Gray. This week's edition is sponsored by Push Security.

You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.

Chongqing, photo by Jerry Wang on Unsplash

A new report describes how a Chinese cyberespionage outfit is using AI to beef up its malware arsenal. If this is a sign of things to come, clustering threat actor behaviour together for attribution purposes is about to get a lot harder.

The Bitdefender report, released last week, describes seven remote access tool (RAT) families. All seven were created by a single cyberespionage actor Bitdefender called SilkParasite and five were previously undocumented. The report authors have medium confidence that SilkParasite is, ahem, a "China-nexus actor" targeting governments across Central Asia including Uzbekistan, Turkmenistan and Kazakhstan. 

Back in November we wrote about what looked like an experiment to see how AI-assisted hacking could support China's Ministry of State Security. The approach those threat actors took at the time was to build an attack framework and let Claude do the hacking. It was error-prone and noisy, but sometimes successful.

SilkParasite, by contrast, is not using AI for yolo hacking. It is using it to support cyberespionage programs where important goals include operating stealthily and not getting caught.

According to Bitdefender, SilkParasite "develops, tests, debugs, and iterates its own tooling, maintains a structured build and deployment workflow, and regularly rotates infrastructure, encryption material, payload names, and persistence artifacts between deployments". 

Rotating its infrastructure and indicators of compromise between deployments makes it harder to detect and link its activities together.

SilkParasite also uses a variety of programming languages and command and control (C2) protocols. Its seven different RATs are written in different languages including .Net, C++, Go, or JavaScript. C2 occurs by abusing Google Drive and internet communication protocols including HTML, HTTP, TCP, DNS and TCP. 

Its malware also typically uses a modular plug-in architecture where additional functionality is only deployed when it is needed. This means initial implants are relatively small and plugins are used to provide capabilities for clipboard monitoring, keylogging, file management, or interactive shell access. This limits the exposure of the entire toolset during any single deployment. It also allows SilkParasite to update or replace individual components without having to change the entire implant. And it minimises the amount it writes to disk, typically only the files required to get its malware up and running.   

For victim organisations, these measures make forensic analysis more complicated. Complete remediation is also more difficult once a particular implant is detected. 

To us, all the behaviours above are the hallmarks of a professional cyberespionage outfit. Of course, doing all of this in a disciplined way is a lot of work, and Bitdefender has evidence SilkParasite is using AI to help it deliver this complex engineering.   

SilkParasite's malware contains indicators of AI-assisted development, such as left-over test functions and placeholder encryption keys. Intriguingly, implants that Bitdefender dubbed GoginRAT and NomadRAT share a high-level architecture even though they are written in Go and C++ respectively and use different C2 protocols and code structure. 

Bitdefender suspects that the same high-level specification document was independently implemented twice with AI assistance. Bitdefender concedes that this structural similarity is not conclusive evidence, but notes that it is the "kind of thing an AI-assisted workflow makes easy".  

This is the first example we've seen where the evidence tells a compelling story of a competent cyberespionage actor incorporating AI into its work practices. SilkParasite is taking the same, disciplined approach to malware development and doing more of it. It’s creating more malware families to build redundancy, make attribution and discovery harder and  reduce the risk of compromise from any single exposure. 

Bitdefender has done a good job describing SilkParasite's malware families and has published Indicators of Compromise. That kind of exposure would once have set the group back significantly. Now that they've figured out how to use AI to speed up their development work, they'll be back better than ever relatively quickly. 

Then the discovery, attribution and publication merry-go-round can start all over again. 

US Throws the Kitchen Sink at Iranian Hackers

In the wake of cyber attacks on its water infrastructure, the US is trying a new trick in its sanctions against Iranian hackers: pointing out they're also hacking Iran's own companies.

Last week, the US government launched Operation Economic Outcast, an "unprecedented campaign" targeting the Iranian government. It included more sanctions, among which were six hackers working on behalf of Iran's Ministry of Intelligence and Security (MOIS).

Three of the hackers are hands-on-keyboard operators responsible for wide-ranging campaigns targeting American organisations including from critical infrastructure and government. The sanctions also named two leaders of the hacking group. 

So far, so normal.

What is new here is that buried in the middle of its 5,300 word press release, the Treasury calls out two of the hackers for targeting Iranian interests:

The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS.  This has driven some of the group to target Iranian companies.  In spring 2025, [one of the group's leaders] Mojtaba Ghal'eh-Kuhi and [hands-on hacker] Saber Shahbazi Balujeh compromised and exfiltrated data from an Iranian telecommunications company.

Hamid Kashfi, a cybersecurity researcher with expertise in Iranian cyberespionage told Seriously Risky Business that previously, being named in sanctions packages had been viewed as a "stamp of approval" within Iran. 

"Some people have been rewarded for that internally", he said.

Kashfi thought that "airing their dirty laundry" and revealing that some individuals had been hacking Iranian companies could cause internal conflict and friction. He said that although hacking for personal gain was a "recognisable pattern" among some Iranian actors, it was still likely that this incident was news to their employers.

So the information itself could plausibly result in repercussions for some of Iran's hackers and therefore impacts on the effectiveness of Iran's cyber operations. We are left wondering, however, about the way it was published: buried in the middle of a Treasury press release, without any corroborating information. 

Is the claim legit? How would the Treasury department know? Why is it buried in the middle of a press release? Why should any Iranian MOIS official or hacker take it seriously?

This reminds us of how the FBI and the KGB attempted to sow discord within target organisations. In these historical examples the agencies planted fraudulent documents or spread false rumors to degrade trust from within an organisation. Although we don't agree with the goals of the operations we've linked to, the agencies running them at least came up with deliberate plans for how and where to disseminate their disinformation. They didn't just bury a claim in a presser.

But whatever, it's fun to see the US government come up with a new way to potentially make things awkward around the office for hackers working for the Iranian state.

AI Is Too Cool to Be Critical

A new report calling for the US government to designate AI as critical infrastructure makes sense, but we also don't think the government should bother.

The report, produced by the nonprofit Americans for Responsible Innovation and first covered by CyberScoop, makes the argument that frontier AI models and associated infrastructure are already a critical infrastructure sector.   

They're probably right, but one purpose of a critical infrastructure designation is to prioritise government resources, and the AI sector is certainly not sitting in the corner being ignored by the government. When frontier labs complained about Chinese distillation, the government response was rapid: Intellectual property theft must be thwarted! 

It's clear the government's attention is already focused on AI, so designating it critical infrastructure, at least for now, would simply be more paperwork for the same resources.

AI should become critical infrastructure when it is boring. Until then, don't bother.  

Watch James Wilson and Tom Uren discuss this edition of the newsletter:

Three Reasons to Be Cheerful This Week:

  1. More granular permissions for Windows 11: Microsoft is testing per-app permission for camera, location and microphone access in new preview builds of Windows 11. Currently, these permissions are granted in a single device-wide setting.    
  2. INTERPOL tackles West African organised crime: INTERPOL has announced that eight-month-long Operation Jackal IV has led to 58 arrests and the identification of 263 suspects. 22 countries participated in the operation. 
  3. Water sector organisation beats CISA red team: A CISA red team report says that an organisation in the water and wastewater sector was able to detect and respond to a simulated cyber intrusion attempt. So there will be some water sector organisations that are well placed to respond to attempted Iranian attacks. 

Sponsor Section

In this Risky Business sponsor interview, James Wilson chats with Push Security’s VP of Research Luke Jennings about how stronger authentication is pushing attackers towards the authorisation layer.

Risky Biz Talks

You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (RSS, iTunes or Spotify).  

In our last "Between Two Nerds" discussion Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack.

Or watch it on YouTube!

From Risky Bulletin:

Russia starts blocking DoH and DoT: Russian internet users started reporting issues with connecting to DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) servers, suggesting the government might have cracked down on the two protocols.

Both DoH and DoT are privacy-centric versions of the DNS protocol that hide a user's DNS queries and intended destination from ISPs and other threat actors on the wire.

Both protocols have seen increased usage in Russia. They are typically used together with a VPN client as a way to bypass the Kremlin's ever-increasing and overbearing internet censorship, and access Western websites.

[more on Risky Bulletin]

Expired cards can be used for new transactions: A team of academics from the University of Massachusetts Amherst have developed an attack that can revive old expired contactless cards to perform new (illegal) transactions.

The attack exploits the fact that NFC card data is not fully encrypted when making a payment and some parameters can be modified without breaking the card's digital hash/signature.

The researchers created a rig that intercepts transaction data through an NFC Man-in-the-Middle attack, updates the expiration date, and relays the modified payment to a Point-of-Sale (POS) terminal.

[more on Risky Bulletin]

Academics find source code overlaps between Geedge and China's Great Firewall: A team of American academics have found source code overlaps between the products of a Chinese tech company and the country's Great Firewall traffic filtering and censorship system.

According to research presented at this year's USENIX security conference, the Chinese government is using the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.

Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.

[more on Risky Bulletin]

Recent Newsletters

  • China's AI-Enabled APT Operations Are Getting Interesting
  • Risky Bulletin: Russia starts blocking DoH and DoT
  • Risky Bulletin: Expired cards can be used for new transactions
  • Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall
  • Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

Recent Videos

  • Risky Business (850): Widespread AI-enabled attacks target Siemens PLCs
  • Between Two Nerds: Attribution is dead, long live attribution
  • Srsly Risky Biz: Trump's private hacker memo is the right idea
  • Risky Business (849): Trump will unleash contractors on cybercriminals
  • James Kettle on inventing new attack techniques with LLMs

Recent Podcasts

  • Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting
  • Risky Bulletin: Russia starts blocking DoH and DoT
  • Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
  • Between Two Nerds: Attribution is dead, long live attribution
  • Risky Bulletin: Expired credit cards can be used for malicious transactions
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517