ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini
Part of a story covered by 3 sources: “SilkParasite-Linked SpiceRAT Infrastructure Traced Back to Mid-2022 Central Asian Espionage” — merged summary and timeline →

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

highThreat actor exploited in the wildimportance 72
AI summary · glm-5.3-flash

Hunt.io linked SpiceRAT, NodeEdgeRAT, and NomadRAT C2 servers to the SilkParasite campaign targeting Central Asian governments since mid-2022.

Hunt.io and researcher Guy Yasur mapped C2 infrastructure tying three of seven RAT families from Bitdefender's SilkParasite report through shared TLS certificates, parent domains, and a cloned RTX Corporation homepage. One certificate spoofing Uzbekistan's state railway was issued by TLC, a CA funded by China's CAICT, and domains impersonate state entities in Turkmenistan, Uzbekistan, Tajikistan, and Kyrgyzstan. Passive DNS pushes the campaign back to mid-2022, and the infrastructure overlaps China-nexus activity including FamousSparrow and IndigoZebra.

  • Shared TLS certificates and parent domains link three RAT families to one SilkParasite campaign.
  • Certificate spoofing Uzbekistan's railway was issued by TLC, a CA funded by China's CAICT.
  • A cloned RTX Corporation homepage hash matched 13 servers across hosting providers and countries.
  • Domains impersonate state entities in Turkmenistan, Uzbekistan, Tajikistan, and Kyrgyzstan.
  • Infrastructure overlaps FamousSparrow and IndigoZebra; passive DNS extends activity to mid-2022.

Indicators of compromiseAll →

TypeIndicatorContext
domaindevon.comgy (sanly.oilgas‑tm[.]com), Uzbek administration (azure.adm‑devon[.]com), and even the Kyrgyz president’s residence (data.yntymak
domaingalkynysh.netfic ministries and state enterprises. Examples include help.galkynysh[.]net (Galkynysh gas field, Turkmenistan), tmgaz‑server[.]com (
domainhunt.iotry of Industry and Information Technology.” In March 2026, Hunt.io identified five SpiceRAT command-and-control servers hosted
domainit.coma deliberate procurement channel. Requests to ns2.asiainfo.it[.]com on 188.190.29[.]126 returned a full copy of RTX Corporati
domainkg.come parent domains and certificates. For example, help.hoster‑kg[.]com (on 193.29.58[.]192) presented the same railway‑spoofing
domainmfa.coms field, Turkmenistan), tmgaz‑server[.]com (Türkmengaz), tm‑mfa[.]com (Turkmenistan’s Ministry of Foreign Affairs), and tojikte
domainordo.comm), and even the Kyrgyz president’s residence (data.yntymak‑ordo[.]com). Bitdefender’s targeting came from lures and infection t
domainserver.com.galkynysh[.]net (Galkynysh gas field, Turkmenistan), tmgaz‑server[.]com (Türkmengaz), tm‑mfa[.]com (Turkmenistan’s Ministry of Fo
domaintdtu.orgtion of hoster‑kg[.]com, not a shared server. Similarly, kg.tdtu[.]org shares a parent domain with mineconom.tdtu[.]org, a Nomad
domaintm.comAdditional domains impersonate Turkmen energy (sanly.oilgas‑tm[.]com), Uzbek administration (azure.adm‑devon[.]com), and even
domaintojiktelecomtj.commfa[.]com (Turkmenistan’s Ministry of Foreign Affairs), and tojiktelecomtj[.]com (Tojiktelecom, Tajikistan). Additional domains impersonat
domainuzrailwaystax.comIt impersonates Uzbekistan’s state railway authority (azure.uzrailwaystax[.]com) and was issued by TLC DV TLS CA, a CA wholly funded by C
Full article920 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 17, 2026

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia.

Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the operation with enough precision to tie three of SilkParasite’s seven RAT families (SpiceRAT, NodeEdgeRAT, and NomadRAT) through shared certificates, domains, and hosting patterns.

“Shared parent domains and an identical TLS certificate connect this infrastructure to hosts Bitdefender attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT, three of the seven malware families documented in the SilkParasite report.” reads the report published by Hunt.io.

“The certificate imitating the Uzbekistan railway entity was issued by TLC, a certificate authority wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology.”

In March 2026, Hunt.io identified five SpiceRAT command-and-control servers hosted by different providers and in different countries. Researchers linked them through several common elements, including the same hostnames, TLS certificates, and a cloned webpage used as the default page.

Instead of focusing only on the malware itself, this approach looks at the infrastructure behind it. Shared certificates or identical webpage hashes can provide strong and practical indicators that defenders can use to identify other servers linked to the campaign.

One certificate in particular stands out. It impersonates Uzbekistan’s state railway authority (azure.uzrailwaystax[.]com) and was issued by TLC DV TLS CA, a CA wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology. The issuer alone isn’t an indicator—nearly 3,000 servers host TLC certificates—but a domain‑validated cert spoofing a Central Asian state entity from a China‑based CA does suggest a deliberate procurement channel.

Requests to ns2.asiainfo.it[.]com on 188.190.29[.]126 returned a full copy of RTX Corporation’s homepage, complete with navigation, subsidiary links, and a stock ticker. The page contained no malicious code and wasn’t unique to that server, but its reuse across the cluster made it a powerful fingerprint.

“Hunt.io’s C2 Infrastructure module tracks servers matching detection signatures for known malware families, including SpiceRAT. In mid-March 2026, we observed a cluster of five active SpiceRAT servers: 46.30.191[.]230188.190.29[.]126193.29.59[.]15931.58.220[.]250, and 171.22.16[.]187. The five were active together in mid-March 2026, across multiple hosting providers and countries.” continues the report.

A HuntSQL query on the page’s SHA‑256 hash returned exactly 13 hosts; three were already in Bitdefender’s SpiceRAT list, two more matched Hunt.io’s SpiceRAT signature, and the remaining eight extended the footprint through shared nginx versions and the same static page.

Why RTX? The report offers two plausible explanations: the page rendered cleanly and was grabbed as a convenient template, or it reflects shared tooling where the clone functions as a default deployment asset. Either way, for defenders it’s a low‑noise, high‑precision signature: byte‑for‑byte identical wherever it lands.

Bitdefender’s SilkParasite report treated several RAT families as distinct, but Hunt.io’s network view shows they share parent domains and certificates. For example, help.hoster‑kg[.]com (on 193.29.58[.]192) presented the same railway‑spoofing certificate, while Bitdefender attributed evo.hoster‑kg[.]com to NodeEdgeRAT; the two are linked through shared registration of hoster‑kg[.]com, not a shared server. Similarly, kg.tdtu[.]org shares a parent domain with mineconom.tdtu[.]org, a NomadRAT C2 indicator in the SilkParasite report.

This doesn’t prove a single operator, but it does show a support function or toolset shared across the campaign. From a detection standpoint, it means pivoting on domains, certificates, and hosting profiles can surface nodes that sample‑based analysis would miss.

The cluster’s domains don’t just look governmental; they spoof specific ministries and state enterprises. Examples include help.galkynysh[.]net (Galkynysh gas field, Turkmenistan), tmgaz‑server[.]com (Türkmengaz), tm‑mfa[.]com (Turkmenistan’s Ministry of Foreign Affairs), and tojiktelecomtj[.]com (Tojiktelecom, Tajikistan). Additional domains impersonate Turkmen energy (sanly.oilgas‑tm[.]com), Uzbek administration (azure.adm‑devon[.]com), and even the Kyrgyz president’s residence (data.yntymak‑ordo[.]com).

Bitdefender’s targeting came from lures and infection telemetry; Hunt.io’s infrastructure analysis names the same sectors with concrete entities. Passive DNS and subdomain enumeration push the timeline back to mid‑2022, suggesting this isn’t a new campaign with a fresh brand—it’s a longer‑running operation now labeled SilkParasite.

SilkParasite overlaps with FamousSparrow, a suspected China‑nexus actor previously seen targeting hotels, governments, and international organizations. The infrastructure also mirrors IndigoZebra (Speccom), documented by Check Point in 2021 as targeting Central Asian ministries with similar domain patterns (mail, service, help) and overlapping naming conventions. These parallels don’t settle attribution, but they do reinforce a consistent operational style across China‑nexus activity in Central Asia.

If you’re responsible for OT/ICS, telecom, or government networks in the region, start by checking your edge and DMZ for the indicators below, especially the RTX page hash and the railway‑spoofing certificate. Monitor for high‑numbered RDP‑over‑TLS ports (64350, 64330, 65535, 65111) on the ASNs most prevalent in the cluster, and watch for domains impersonating local hosting providers or state entities. The original Hunt.io post includes the full IoC tables and HuntSQL queries; linking to it is essential for precise awareness and for teams that want to reproduce the pivots.

“The targeting picture that emerges from this infrastructure, named ministries and state enterprises across five Central Asian countries dating back to at least mid-2022 suggests SilkParasite is a more recent label for an operation with much longer and wider footprint.” concludes the report. “Organizations in the affected sectors and regions can make use of the above indicators and observations to assess their own exposure.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SilkParasite)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html