Bitdefender Labs research · 19 August 2026

The operator stays at the keyboard.

The AI traces are small. The central finding is an espionage operation run like a software project: seven RAT families, capabilities delivered on demand and commands carried through Google Drive.

Read the Bitdefender research [2]

The short story that travels

PROMPTAIMALWAREAUTOMATED ATTACK

The documented path

  1. Human operators
  2. Development process
  3. Selective AI traces
  4. Lure document
  5. Small implant
  6. Google Drive
  7. Operator-selected module
AI appears in two lure documents and a few pieces of code residue. People choose targets, maintain variants and issue commands. Bitdefender rates both AI-assisted development and the campaign's connection to a China-nexus espionage environment at medium confidence. [1]

The same events, two readings

A shared folder looks ordinary until you know its purpose.

Choose a perspective. The Drive operations stay the same while their meaning changes. This diagram simplifies the DriveSilkRAT flow documented by Bitdefender. [1] [2]

Perspective

What the network sees

Allowed traffic to a familiar service

A process lists files, downloads one object and uploads another through the Google Drive API. No new attacker-owned command domain appears.

Compromised computer
shared / ops / 29 Shared folder
Human operator
  1. 09:14:03 files.list
    File listing

    A process checks a folder through the Drive API.

  2. 09:14:08 files.get
    Download

    One file moves from the cloud service to the computer.

  3. 09:14:09 local
    Local activity

    No connection opens to a new external domain.

  4. 09:14:37 files.create
    Upload

    One file returns to the same shared folder.

What the operator does

A command queue concealed inside a shared folder

The implant looks for a task, downloads the operator's chosen module, runs it in memory and writes the result to the same folder.

Compromised computer
shared / ops / 29 Shared folder
Human operator
  1. 09:14:03 files.list
    The implant looks for tasks

    DriveSilkRAT checks whether the operator has left a command.

  2. 09:14:08 files.get
    The command and module reach the target

    The implant downloads only the capability needed at that moment.

  3. 09:14:09 local
    The module runs in memory

    Execution avoids leaving the full capability set on disk.

  4. 09:14:37 files.create
    The result returns

    The operator receives it through the same trusted service.

The network perspective is displayed.

Google Drive was the channel. The research does not say that Google's service was compromised.

12 recovered .NET modules
DriveSilkRAT could load them into memory.
Roughly 65 identifiers
An upper bound, not a victim count. The set includes real, test and operator-controlled systems; one computer could produce more than one identifier.

Operation manifest

Seven families limit how much capability is exposed at once.

Nearly every family can add capabilities only when an operator needs them. NodeEdgeRAT is the exception and ships everything in one script. [1]

5/7were previously undocumented

Comparison based on Bitdefender's published technical table. This is not a victim inventory.
Family Implementation Status Channel Extension model
DriveSilkRAT .NET · C++ Previously undocumented Google Drive, trusted service 12 recovered .NET modules, loaded in memory
SpiceRAT C/C++ Previously known HTTP, M247 hosting Downloaded DLL modules, reflectively loaded
CookiETagRAT C++ Previously undocumented HTTP Cookie and ETag headers PE modules mapped into memory
BloodAlchemy C/C++ Previously known TCP, HTTP(S), DNS and SMB 3 recovered embedded modules, plus on-demand modules
NomadRAT C++ Previously undocumented HTTPS PE modules fetched by ID, with a local fallback path
GoginRAT Go Previously undocumented HTTP Encrypted local modules, loaded only when requested
NodeEdgeRAT JavaScript Previously undocumented HTTPS No modules, every capability ships in one script

The portfolio uses four implementation groups: .NET, C/C++, Go and JavaScript. Changes to languages, keys, addresses and packaging across builds contributed to Bitdefender's assessment that the operation had a maintained development process. [2]

Traces in the files

AI appears in two lure documents and a few code details.

No code clue proves AI use on its own. Bitdefender considered them together and kept the conclusion at medium confidence. [1] [2]

  1. Stronger evidence

    Two lure documents

    Bitdefender classifies them as AI-generated. The research does not identify a model or vendor.

  2. Suggestive clues

    Residue in release builds

    GoginRAT retained test functions and the key 0123456789abcdef. NodeEdgeRAT contained the value change_this_key.

  3. Cumulative assessment

    Similar architectures

    NomadRAT in C++ and GoginRAT in Go follow closely related high-level designs. Bitdefender says AI assistance could explain the similarity.

Attribution and limits

The evidence points to a China-nexus espionage environment. The exact author remains unknown.

Bitdefender uses the term China-nexus and a medium-confidence rating. That wording preserves the distance between supporting indicators and the identity of a service or unit. [1] [3]

  1. Directly observed

    Artifacts and activity

    Seven RAT families, lure documents, infrastructure, a Google Drive folder used for tasking and 37 commands with analysed server-side timestamps.

  2. Supports the assessment

    Relationships and context

    SpiceRAT had been linked to SneakyChef, which Cisco assessed with medium confidence as likely Chinese-speaking. China Unicom addresses, the target profile and working hours consistent with UTC+8 add support.

  3. Published conclusion

    China-nexus, medium confidence

    The indicators support a connection to a tooling and practice environment associated with Chinese espionage. Tool reuse does not establish that SilkParasite and SneakyChef are the same actor.

  4. Unknown

    Who gives the orders

    No public evidence identifies a Chinese service, military unit, contractor, complete victim list or the intelligence taken.

The Romanian connection

The research comes from Bitdefender Labs, part of a company with its global headquarters in Bucharest.

The mechanism observed in Central Asia raises a practical question for any ministry or energy organisation that allows cloud services: which process generated the traffic, and was there a real user action? [5]

  1. Drive traffic without a user action

    Bitdefender recommends examining Google Drive traffic that does not correspond to user-initiated activity.

  2. A signed application in an unexpected place

    A legitimate application running from an unusual folder and loading an unfamiliar DLL beside it warrants investigation.

Each relationship is an investigation lead. Neither proves a compromise on its own. [1]

Method and sources

Observed fact, assessment and hypothesis are labelled separately.

This page summarizes the technical research published by Bitdefender Labs on 19 August 2026. Cisco Talos supports the earlier relationship between SpiceRAT and SneakyChef. The Record confirms the publication and main findings, but this page does not adopt its stronger wording about origin or infection counts.

Research published 19 August. Independent coverage 20 August. Sources rechecked 23 August 2026.

  1. 1
    Bitdefender Labs, SilkParasite research article

    Primary source · 19 August 2026

  2. 2
    Bitdefender Labs, full technical report

    Primary source · 62-page PDF

  3. 3
    Cisco Talos, SpiceRAT and SneakyChef

    Earlier research · 21 June 2024

  4. 4
    The Record, independent coverage

    Specialist press · 20 August 2026

  5. 5
    Bitdefender, global headquarters in Bucharest

    Official company page