ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 2 sources: “SilkParasite-Linked SpiceRAT Infrastructure Traced Back to 2022 in China-Nexus Espionage Targeting Central Asia” — merged summary and timeline →

SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia

highThreat actor exploited in the wildimportance 60
AI summary · glm-5.3-flash

Hunt.io links SpiceRAT C2 servers to China-nexus SilkParasite espionage targeting Central Asian governments, with related infrastructure active since 2022.

Hunt.io and researcher Guy Yasur traced a cluster of SpiceRAT command-and-control servers active from late 2025 to August 2026 to infrastructure linked to the China-nexus SilkParasite espionage operation. Shared parent domains, a certificate resembling an Uzbek railway entity, and a cloned RTX Corporation homepage appearing on 13 servers connect SpiceRAT systems to NodeEdgeRAT and NomadRAT infrastructure. Passive DNS records show related subdomains as early as mid-2022, suggesting the infrastructure has existed for at least four years. Hostnames impersonate government, energy and telecom targets across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.

  • Hunt.io and Guy Yasur tied SpiceRAT servers to the SilkParasite espionage operation via infrastructure analysis.
  • Shared domains, reused certificates and a cloned RTX homepage connect SpiceRAT, NodeEdgeRAT and NomadRAT systems.
  • Passive DNS extends the timeline to mid-2022, suggesting SilkParasite is a newer label for a longer-running effort.
  • Infrastructure names impersonate government, energy and telecom organizations in five Central Asian countries.
  • Defenders are advised to hunt published IoCs in DNS and certificate data and restrict remote-access exposure.

Indicators of compromiseAll →

TypeIndicatorContext
domainadm-devon.comated with Uzbek administration-themed spoofing Domain azure.adm-devon[.]com Uzbek administration-themed domain IP Address 5.183.95[.]
domaincwisuz.com]net Domain impersonating the Galkynysh gas field Domain kg.cwisuz[.]com Domain observed on the same host IP Address 45.153.127[.]
domaindevon-uz.com.]com NodeEdgeRAT-related sibling hostname Domain uzrailway.devon-uz[.]com BloodAlchemy-related railway-themed domain SHA-256 Hash 2
domaindushanbeidc.orgsharing the LokiDev self-signed certificate Domain normativ.dushanbeidc[.]org Domain impersonating Tajikistan’s national IT hub project
domaingalkynysh.netciated with Central Asian energy-themed domains Domain help.galkynysh[.]net Domain impersonating the Galkynysh gas field Domain kg.cw
domainhoster-kg.comHost presenting the spoofed railway certificate Domain help.hoster-kg[.]com Domain linked to NodeEdgeRAT registration activity Domain
domainhpsupporter.comHost with high-numbered remote desktop exposure Domain api.hpsupporter[.]com Support-themed infrastructure domain IP Address 46.30.191
domainhunt.iolowing operators to collect information and issue commands. Hunt.io analysts, working with researcher Guy Yasur, identified a c
domaininfocomkg.orgst with high-numbered remote desktop exposure Domain center.infocomkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.]
domainit.come RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source – Hunt.io) The certificate was issued by TLC, a c
domainminings.blogeRAT host serving the copied RTX page Domain infrastructure.minings[.]blog Domain observed on copied RTX page infrastructure IP Addr
domainmpekz.onlinessociated with Kazakh government-themed spoofing Domain gov.mpekz[.]online Kazakhstan government-themed domain IP Address 46.30.191[
domainnatcommunzu.comst associated with Uzbek telecom-themed spoofing Domain tmk.natcommunzu[.]com Uzbekistan communications-themed domain IP Address 46.30.
domainoilgas-tm.comassociated with Turkmen energy-themed spoofing Domain sanly.oilgas-tm[.]com Turkmen energy-themed domain IP Address 45.86.162[.]141 H
domainpanterstationary.online31.59.185[.]224 Host serving the copied RTX page Domain ns.panterstationary[.]online Domain observed on copied RTX page infrastructure Domain
domainplan-mail.com58.209[.]28 Host serving the copied RTX page Domain infoxxe.plan-mail[.]com Domain observed on copied RTX page infrastructure Domain
domainpostmfa.comHost with high-numbered remote desktop exposure Domain mail.postmfa[.]com Foreign affairs-themed mail domain IP Address 45.153.127[
domainpresldent.infot associated with presidential-themed spoofing Domain state.presldent[.]info Presidential-themed typosquatting domain IP Address 46.30
domainskycom.supporttorical resolution for ns2.asiainfo.it[.]com Domain manager.skycom[.]support SpiceRAT-related hostname IP Address 194.68.225[.]168 His
domainsozandagon.orgassociated with Tajikistan-themed spoofing Domain normativ.sozandagon[.]org Tajikistan-themed domain IP Address 192.121.87[.]172 Host
domaintaustas.comomain observed on copied RTX page infrastructure Domain pro.taustas[.]com Domain observed on copied RTX page infrastructure IP Addr
domaintdtu.orgmkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.]org Domain sharing a parent domain with NomadRAT infrastructu
domaintmgaz-server.comserving copied RTX page and spoofed certificate Domain www.tmgaz-server[.]com Domain impersonating Türkmengaz IP Address 46.30.188[.]54
domaintojiktelecomtj.com46.30.188[.]54 Host serving the copied RTX page Domain www.tojiktelecomtj[.]com Domain impersonating Tojiktelecom IP Address 31.58.209[.]
domainuzrailwaystax.comss 2.58.14[.]95 Hunt.io-detected SpiceRAT host Domain azure.uzrailwaystax[.]com Spoofed Uzbek railway-themed domain IP Address 31.59.185[
domainwww.tm-mfa.coms 185.243.114[.]124 Host serving the copied RTX page Domain www[.]tm-mfa[.]com Domain observed on copied RTX page infrastructure IP Ad
domainyntymak-ord.comciated with Kyrgyz presidential-themed spoofing Domain data.yntymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19
domainyntymak-ordo.comated with Kyrgyz presidential-themed spoofing Domain center.yntymak-ordo[.]com Kyrgyz presidential residence-themed domain IP Address 45
domainytnymak-ord.comciated with Kyrgyz presidential-themed spoofing Domain link.ytnymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19
sha19297d5fd21ef21b16f5880cd4faea2ad1fb9ee396 fingerprint of the spoofed railway certificate SHA-1 Hash 9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39 SHA-1 fingerprint of the spoofed railway certificate JA4X F
sha25627e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4com BloodAlchemy-related railway-themed domain SHA-256 Hash 27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4 SHA-256 fingerprint of the spoofed railway certificate SHA-
sha256e9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382orical resolution for manager.skycom[.]support SHA-256 Hash E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382 Hash of the copied RTX Corporation web page IP Address 185.
Full article1,584 words · extracted from cybersecuritynews.com · click to collapse

SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity behind the campaign may be older and broader than its recent name suggests.

The operation has used spear-phishing emails carrying convincing government-themed documents and trusted Windows programs to plant remote-access malware. These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.

Hunt.io analysts, working with researcher Guy Yasur, identified a connected group of SpiceRAT command-and-control servers active from late 2025 to August 2026.

Hunt.io said in a report shared with Cyber Security News (CSN) that the infrastructure links to SilkParasite, which used seven remote-access toolsets against Central Asian governments.

The discovery matters because it joins seemingly separate systems through repeated technical traces rather than one malware sample. Public-facing infrastructure can reveal how a long-running spying operation builds and reuses its systems.

SilkParasite-Linked Malware Infrastructure

The shared parent domains, a matching digital certificate and a copied web page connect SpiceRAT servers to systems attributed to NodeEdgeRAT and NomadRAT. This does not prove one operator controls every host, but suggests a common operation or shared support function.

Analysts first flagged SpiceRAT-related servers in late 2025 using earlier detection logic. In March 2026, five servers appeared within days across different providers and countries. Shared hostnames and certificates were stronger links, because a detection only shows what ran on one machine.

One recurring decoy was a complete but outdated copy of an RTX Corporation homepage. The page contained no malicious code, credential form or delivery mechanism.

Yet its identical content hash appeared on 13 servers and gave researchers a reliable way to map infrastructure that otherwise looked unrelated, much like patterns seen in remote access malware operations.

Certificate reuse strengthened the link. A certificate made to resemble an Uzbek railway entity appeared on eight hosts, including systems carrying the cloned page.

Screenshot of the RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source - Hunt.io)
Screenshot of the RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source – Hunt.io)

The certificate was issued by TLC, a certificate authority operated by an organization funded by China’s state-linked communications research institute, although the issuer alone is not an indicator of malicious activity.

Passive DNS records extended the timeline further. Related subdomains were seen as early as mid-2022, suggesting the infrastructure has existed for at least four years. This suggests SilkParasite may be a newer label for a longer-running effort.

Central Asian Targets and Defense

The infrastructure used names resembling government agencies, state energy operators and telecom organizations across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.

These names should be treated as apparent impersonation targets, not evidence that the named organizations were breached. Hunt.io said it notified affected organizations and relevant national CERTs before publication.

The targeting overlaps with China-linked SilkParasite espionage campaign, which used document lures and a mix of established and newly documented remote-access tools.

That report assessed a China-nexus link with medium confidence. The newer network evidence offers useful context, but it does not independently establish attribution.

Researchers also noted naming similarities with infrastructure previously tied to suspected China-nexus activity known as IndigoZebra, as well as overlaps cited with FamousSparrow.

Such patterns can result from shared tools, service providers or conventions, so they are leads for investigation rather than proof of a direct operational relationship.

For defenders, the practical lesson is to search network logs, DNS records and certificate data for the indicators published below, especially in the affected sectors.

Teams should review unusual remote desktop exposure and investigate lookalike domains promptly. Recent cases involving malware abusing developer tunnels show why outbound connections and remote-management paths deserve continuous scrutiny.

Organizations should also strengthen phishing defenses, verify unexpected government-themed documents through separate channels, restrict unnecessary remote access and monitor for repeated web-page or certificate artifacts.

Correlating those signals can expose staging and command systems that may not be caught by endpoint detections alone, giving incident responders a broader picture of potential exposure. This includes systems with privileged access to critical services.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP Address46.30.191[.]230SpiceRAT server observed in the March 2026 cluster
IP Address188.190.29[.]126SpiceRAT infrastructure and cloned RTX page host
IP Address193.29.59[.]159SpiceRAT server observed in the March 2026 cluster
IP Address31.58.220[.]250SpiceRAT server observed in the March 2026 cluster
IP Address171.22.16[.]187SpiceRAT server observed in the March 2026 cluster
Domainns2.asiainfo.it[.]comHostname associated with SpiceRAT infrastructure
IP Address185.122.185[.]36Historical resolution for ns2.asiainfo.it[.]com
IP Address194.71.107[.]243Historical resolution for ns2.asiainfo.it[.]com
Domainmanager.skycom[.]supportSpiceRAT-related hostname
IP Address194.68.225[.]168Historical resolution for manager.skycom[.]support
IP Address194.14.217[.]119Historical resolution for manager.skycom[.]support
SHA-256 HashE9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382Hash of the copied RTX Corporation web page
IP Address185.243.114[.]124Host serving the copied RTX page
Domainwww[.]tm-mfa[.]comDomain observed on copied RTX page infrastructure
IP Address185.243.115[.]156Host serving the copied RTX page
IP Address45.153.125[.]200Reported SpiceRAT host serving the copied RTX page
IP Address194.68.44[.]133Reported SpiceRAT host serving the copied RTX page
Domaininfrastructure.minings[.]blogDomain observed on copied RTX page infrastructure
IP Address2.58.14[.]95Hunt.io-detected SpiceRAT host
Domainazure.uzrailwaystax[.]comSpoofed Uzbek railway-themed domain
IP Address31.59.185[.]224Host serving the copied RTX page
Domainns.panterstationary[.]onlineDomain observed on copied RTX page infrastructure
Domainpro.taustas[.]comDomain observed on copied RTX page infrastructure
IP Address2.58.15[.]172Host serving the copied RTX page
IP Address188.190.18[.]208Host serving copied RTX page and spoofed certificate
Domainwww.tmgaz-server[.]comDomain impersonating Türkmengaz
IP Address46.30.188[.]54Host serving the copied RTX page
Domainwww.tojiktelecomtj[.]comDomain impersonating Tojiktelecom
IP Address31.58.209[.]28Host serving the copied RTX page
Domaininfoxxe.plan-mail[.]comDomain observed on copied RTX page infrastructure
Domainmail.plan-mail[.]comDomain observed on copied RTX page infrastructure
IP Address45.153.125[.]20Reported SpiceRAT host and certificate host
IP Address31.57.92[.]84Host serving the copied RTX page
IP Address185.243.114[.]238Host sharing the LokiDev self-signed certificate
Domainnormativ.dushanbeidc[.]orgDomain impersonating Tajikistan’s national IT hub project
IP Address92.243.66[.]71Host presenting the spoofed railway certificate
IP Address193.29.56[.]119Host presenting the spoofed railway certificate
IP Address193.29.57[.]182Host presenting the spoofed railway certificate
Domainhelp.hoster-kg[.]comDomain linked to NodeEdgeRAT registration activity
Domainevo.hoster-kg[.]comNodeEdgeRAT-related sibling hostname
Domainuzrailway.devon-uz[.]comBloodAlchemy-related railway-themed domain
SHA-256 Hash27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4SHA-256 fingerprint of the spoofed railway certificate
SHA-1 Hash9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39SHA-1 fingerprint of the spoofed railway certificate
JA4X Fingerprinta373a9f83c6b_7022c563de38_4eebb5e6ba4eJA4X fingerprint associated with the TLC-issued certificate
Certificate Serial81628176171941507003526847276457465393Serial number of the spoofed railway certificate
IP Address46.30.189[.]191Host associated with presidential-themed spoofing
Domainstate.presldent[.]infoPresidential-themed typosquatting domain
IP Address46.30.191[.]214Historical host for presidential-themed spoofing
Domaincert.presldent[.]infoPresidential-themed typosquatting subdomain
IP Address45.86.163[.]87Historical host for presidential-themed spoofing
Domaincheck.presldent[.]infoPresidential-themed typosquatting subdomain
IP Address2.58.15[.]101Historical host for presidential-themed spoofing
Domainchief.presldent[.]infoPresidential-themed typosquatting subdomain
IP Address185.253.117[.]32Historical host for presidential-themed spoofing
Domainit.presldent[.]infoPresidential-themed typosquatting subdomain
IP Address193.29.57[.]159Host associated with Uzbek telecom-themed spoofing
Domaintmk.natcommunzu[.]comUzbekistan communications-themed domain
IP Address46.30.190[.]170Historical host for Uzbek telecom-themed spoofing
Domainmicrosoft.natcommunzu[.]comSubdomain under the communications-themed domain
IP Address185.243.112[.]253Historical SpiceRAT-related infrastructure host
Domainstorage.natcommunzu[.]comEarliest related subdomain observed in July 2022
IP Address185.243.112[.]220Historical infrastructure host
Domainsupport.natcommunzu[.]comRelated communications-themed subdomain
IP Address45.67.230[.]185Historical infrastructure host
Domainuz.natcommunzu[.]comRelated communications-themed subdomain
IP Address91.132.94[.]36Host associated with Central Asian energy-themed domains
Domainhelp.galkynysh[.]netDomain impersonating the Galkynysh gas field
Domainkg.cwisuz[.]comDomain observed on the same host
IP Address45.153.127[.]186Host associated with Kazakh government-themed spoofing
Domaingov.mpekz[.]onlineKazakhstan government-themed domain
IP Address46.30.191[.]232Host associated with Tajikistan-themed spoofing
Domainnormativ.sozandagon[.]orgTajikistan-themed domain
IP Address192.121.87[.]172Host associated with Kyrgyz presidential-themed spoofing
Domaindata.yntymak-ord[.]comKyrgyz presidential residence-themed domain
IP Address193.29.58[.]217Host associated with Kyrgyz presidential-themed spoofing
Domainlink.ytnymak-ord[.]comKyrgyz presidential residence-themed domain
IP Address195.88.191[.]70Host associated with Kyrgyz presidential-themed spoofing
Domaincenter.yntymak-ordo[.]comKyrgyz presidential residence-themed domain
IP Address45.153.127[.]38Host associated with Uzbek administration-themed spoofing
Domainazure.adm-devon[.]comUzbek administration-themed domain
IP Address5.183.95[.]49Host associated with Uzbek administration-themed spoofing
Domainuz.adm-devon[.]comUzbek administration-themed domain
IP Address195.88.191[.]250Host associated with Turkmen energy-themed spoofing
Domainsanly.oilgas-tm[.]comTurkmen energy-themed domain
IP Address45.86.162[.]141Host with high-numbered remote desktop exposure
Domainmail.postmfa[.]comForeign affairs-themed mail domain
IP Address45.153.127[.]99Host with high-numbered remote desktop exposure
Domaincenter.infocomkg[.]orgKyrgyzstan communications-themed domain
Domainkg.tdtu[.]orgDomain sharing a parent domain with NomadRAT infrastructure
IP Address194.14.217[.]199Infrastructure host associated with Kyrgyzstan-themed spoofing
Domainmail.infocomkg[.]orgKyrgyzstan communications-themed mail domain
IP Address83.242.96[.]242Infrastructure host associated with Kyrgyzstan-themed spoofing
Domainservice.infocomkg[.]orgKyrgyzstan communications-themed service domain
IP Address185.253.116[.]145Infrastructure host associated with related domains
Domaininfo.tdtu[.]orgRelated domain under the tdtu[.]org parent
IP Address193.29.59[.]248Infrastructure host associated with related domains
Domainud.tdtu[.]orgRelated domain under the tdtu[.]org parent
IP Address5.183.95[.]7Host with high-numbered remote desktop exposure
Domainapi.hpsupporter[.]comSupport-themed infrastructure domain
IP Address46.30.191[.]90Infrastructure host associated with support-themed spoofing
Domaincheckup.hpsupporter[.]comSupport-themed infrastructure domain
IP Address2.58.15[.]129Infrastructure host associated with support-themed spoofing
Domainhelp.hpsupporter[.]comSupport-themed infrastructure domain
IP Address45.86.162[.]249Infrastructure host associated with support-themed spoofing
Domaintelecom.hpsupporter[.]comSupport-themed telecommunications domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/silkparasite-linked-malware/