Seriously Risky Business Newsletter
August 27, 2026
China's AI-Enabled APT Operations Are Getting Interesting
Presented by
Policy & Intelligence
A new report describes how a Chinese cyberespionage outfit is using AI to beef up its malware arsenal. If this is a sign of things to come, clustering threat actor behaviour together for attribution purposes is about to get a lot harder.
The Bitdefender report, released last week, describes seven remote access tool (RAT) families. All seven were created by a single cyberespionage actor Bitdefender called SilkParasite and five were previously undocumented. The report authors have medium confidence that SilkParasite is, ahem, a "China-nexus actor" targeting governments across Central Asia including Uzbekistan, Turkmenistan and Kazakhstan.
Back in November we wrote about what looked like an experiment to see how AI-assisted hacking could support China's Ministry of State Security. The approach those threat actors took at the time was to build an attack framework and let Claude do the hacking. It was error-prone and noisy, but sometimes successful.