SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Hunt.io links SpiceRAT C2 servers to China-nexus SilkParasite espionage targeting Central Asian governments, with related infrastructure active since 2022.
Hunt.io and researcher Guy Yasur traced a cluster of SpiceRAT command-and-control servers active from late 2025 to August 2026 to infrastructure linked to the China-nexus SilkParasite espionage operation. Shared parent domains, a certificate resembling an Uzbek railway entity, and a cloned RTX Corporation homepage appearing on 13 servers connect SpiceRAT systems to NodeEdgeRAT and NomadRAT infrastructure. Passive DNS records show related subdomains as early as mid-2022, suggesting the infrastructure has existed for at least four years. Hostnames impersonate government, energy and telecom targets across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.
- Hunt.io and Guy Yasur tied SpiceRAT servers to the SilkParasite espionage operation via infrastructure analysis.
- Shared domains, reused certificates and a cloned RTX homepage connect SpiceRAT, NodeEdgeRAT and NomadRAT systems.
- Passive DNS extends the timeline to mid-2022, suggesting SilkParasite is a newer label for a longer-running effort.
- Infrastructure names impersonate government, energy and telecom organizations in five Central Asian countries.
- Defenders are advised to hunt published IoCs in DNS and certificate data and restrict remote-access exposure.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | adm-devon.com | ated with Uzbek administration-themed spoofing Domain azure.adm-devon[.]com Uzbek administration-themed domain IP Address 5.183.95[.] |
| domain | cwisuz.com | ]net Domain impersonating the Galkynysh gas field Domain kg.cwisuz[.]com Domain observed on the same host IP Address 45.153.127[.] |
| domain | devon-uz.com | .]com NodeEdgeRAT-related sibling hostname Domain uzrailway.devon-uz[.]com BloodAlchemy-related railway-themed domain SHA-256 Hash 2 |
| domain | dushanbeidc.org | sharing the LokiDev self-signed certificate Domain normativ.dushanbeidc[.]org Domain impersonating Tajikistan’s national IT hub project |
| domain | galkynysh.net | ciated with Central Asian energy-themed domains Domain help.galkynysh[.]net Domain impersonating the Galkynysh gas field Domain kg.cw |
| domain | hoster-kg.com | Host presenting the spoofed railway certificate Domain help.hoster-kg[.]com Domain linked to NodeEdgeRAT registration activity Domain |
| domain | hpsupporter.com | Host with high-numbered remote desktop exposure Domain api.hpsupporter[.]com Support-themed infrastructure domain IP Address 46.30.191 |
| domain | hunt.io | lowing operators to collect information and issue commands. Hunt.io analysts, working with researcher Guy Yasur, identified a c |
| domain | infocomkg.org | st with high-numbered remote desktop exposure Domain center.infocomkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.] |
| domain | it.com | e RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source – Hunt.io) The certificate was issued by TLC, a c |
| domain | minings.blog | eRAT host serving the copied RTX page Domain infrastructure.minings[.]blog Domain observed on copied RTX page infrastructure IP Addr |
| domain | mpekz.online | ssociated with Kazakh government-themed spoofing Domain gov.mpekz[.]online Kazakhstan government-themed domain IP Address 46.30.191[ |
| domain | natcommunzu.com | st associated with Uzbek telecom-themed spoofing Domain tmk.natcommunzu[.]com Uzbekistan communications-themed domain IP Address 46.30. |
| domain | oilgas-tm.com | associated with Turkmen energy-themed spoofing Domain sanly.oilgas-tm[.]com Turkmen energy-themed domain IP Address 45.86.162[.]141 H |
| domain | panterstationary.online | 31.59.185[.]224 Host serving the copied RTX page Domain ns.panterstationary[.]online Domain observed on copied RTX page infrastructure Domain |
| domain | plan-mail.com | 58.209[.]28 Host serving the copied RTX page Domain infoxxe.plan-mail[.]com Domain observed on copied RTX page infrastructure Domain |
| domain | postmfa.com | Host with high-numbered remote desktop exposure Domain mail.postmfa[.]com Foreign affairs-themed mail domain IP Address 45.153.127[ |
| domain | presldent.info | t associated with presidential-themed spoofing Domain state.presldent[.]info Presidential-themed typosquatting domain IP Address 46.30 |
| domain | skycom.support | torical resolution for ns2.asiainfo.it[.]com Domain manager.skycom[.]support SpiceRAT-related hostname IP Address 194.68.225[.]168 His |
| domain | sozandagon.org | associated with Tajikistan-themed spoofing Domain normativ.sozandagon[.]org Tajikistan-themed domain IP Address 192.121.87[.]172 Host |
| domain | taustas.com | omain observed on copied RTX page infrastructure Domain pro.taustas[.]com Domain observed on copied RTX page infrastructure IP Addr |
| domain | tdtu.org | mkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.]org Domain sharing a parent domain with NomadRAT infrastructu |
| domain | tmgaz-server.com | serving copied RTX page and spoofed certificate Domain www.tmgaz-server[.]com Domain impersonating Türkmengaz IP Address 46.30.188[.]54 |
| domain | tojiktelecomtj.com | 46.30.188[.]54 Host serving the copied RTX page Domain www.tojiktelecomtj[.]com Domain impersonating Tojiktelecom IP Address 31.58.209[.] |
| domain | uzrailwaystax.com | ss 2.58.14[.]95 Hunt.io-detected SpiceRAT host Domain azure.uzrailwaystax[.]com Spoofed Uzbek railway-themed domain IP Address 31.59.185[ |
| domain | www.tm-mfa.com | s 185.243.114[.]124 Host serving the copied RTX page Domain www[.]tm-mfa[.]com Domain observed on copied RTX page infrastructure IP Ad |
| domain | yntymak-ord.com | ciated with Kyrgyz presidential-themed spoofing Domain data.yntymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19 |
| domain | yntymak-ordo.com | ated with Kyrgyz presidential-themed spoofing Domain center.yntymak-ordo[.]com Kyrgyz presidential residence-themed domain IP Address 45 |
| domain | ytnymak-ord.com | ciated with Kyrgyz presidential-themed spoofing Domain link.ytnymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19 |
| sha1 | 9297d5fd21ef21b16f5880cd4faea2ad1fb9ee39 | 6 fingerprint of the spoofed railway certificate SHA-1 Hash 9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39 SHA-1 fingerprint of the spoofed railway certificate JA4X F |
| sha256 | 27e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4 | com BloodAlchemy-related railway-themed domain SHA-256 Hash 27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4 SHA-256 fingerprint of the spoofed railway certificate SHA- |
| sha256 | e9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382 | orical resolution for manager.skycom[.]support SHA-256 Hash E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382 Hash of the copied RTX Corporation web page IP Address 185. |
Full article1,584 words · extracted from cybersecuritynews.com · click to collapse
SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity behind the campaign may be older and broader than its recent name suggests.
The operation has used spear-phishing emails carrying convincing government-themed documents and trusted Windows programs to plant remote-access malware. These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.
Hunt.io analysts, working with researcher Guy Yasur, identified a connected group of SpiceRAT command-and-control servers active from late 2025 to August 2026.
Hunt.io said in a report shared with Cyber Security News (CSN) that the infrastructure links to SilkParasite, which used seven remote-access toolsets against Central Asian governments.
The discovery matters because it joins seemingly separate systems through repeated technical traces rather than one malware sample. Public-facing infrastructure can reveal how a long-running spying operation builds and reuses its systems.
SilkParasite-Linked Malware Infrastructure
The shared parent domains, a matching digital certificate and a copied web page connect SpiceRAT servers to systems attributed to NodeEdgeRAT and NomadRAT. This does not prove one operator controls every host, but suggests a common operation or shared support function.
Analysts first flagged SpiceRAT-related servers in late 2025 using earlier detection logic. In March 2026, five servers appeared within days across different providers and countries. Shared hostnames and certificates were stronger links, because a detection only shows what ran on one machine.
One recurring decoy was a complete but outdated copy of an RTX Corporation homepage. The page contained no malicious code, credential form or delivery mechanism.
Yet its identical content hash appeared on 13 servers and gave researchers a reliable way to map infrastructure that otherwise looked unrelated, much like patterns seen in remote access malware operations.
Certificate reuse strengthened the link. A certificate made to resemble an Uzbek railway entity appeared on eight hosts, including systems carrying the cloned page.
![Screenshot of the RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source - Hunt.io)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrfbFt5eCp8kgSb8X63qJtmHVlsE74AvmZvWHf9b6mmPdsia2TbZpjZK560Xmf1tZHR0cdscCdXlNj05u6ggrElty-9G9fIY1P0x9PVZCGwqkWVQuN5aliEhtYAj6QkNK12MVrjEAdSBDfZDMG2DjUbcUZipJSt5KTQAIqiX087HcsCOAqkJ4OskpqIW4/s1600/Screenshot%20of%20the%20RTX%20Corporation%20impersonation%20page%20hosted%20on%20ns2.asiainfo.it%5B.%5Dcom%20(Source%20-%20Hunt.io).webp)
The certificate was issued by TLC, a certificate authority operated by an organization funded by China’s state-linked communications research institute, although the issuer alone is not an indicator of malicious activity.
Passive DNS records extended the timeline further. Related subdomains were seen as early as mid-2022, suggesting the infrastructure has existed for at least four years. This suggests SilkParasite may be a newer label for a longer-running effort.
Central Asian Targets and Defense
The infrastructure used names resembling government agencies, state energy operators and telecom organizations across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.
These names should be treated as apparent impersonation targets, not evidence that the named organizations were breached. Hunt.io said it notified affected organizations and relevant national CERTs before publication.
The targeting overlaps with China-linked SilkParasite espionage campaign, which used document lures and a mix of established and newly documented remote-access tools.
That report assessed a China-nexus link with medium confidence. The newer network evidence offers useful context, but it does not independently establish attribution.
Researchers also noted naming similarities with infrastructure previously tied to suspected China-nexus activity known as IndigoZebra, as well as overlaps cited with FamousSparrow.
Such patterns can result from shared tools, service providers or conventions, so they are leads for investigation rather than proof of a direct operational relationship.
For defenders, the practical lesson is to search network logs, DNS records and certificate data for the indicators published below, especially in the affected sectors.
Teams should review unusual remote desktop exposure and investigate lookalike domains promptly. Recent cases involving malware abusing developer tunnels show why outbound connections and remote-management paths deserve continuous scrutiny.
Organizations should also strengthen phishing defenses, verify unexpected government-themed documents through separate channels, restrict unnecessary remote access and monitor for repeated web-page or certificate artifacts.
Correlating those signals can expose staging and command systems that may not be caught by endpoint detections alone, giving incident responders a broader picture of potential exposure. This includes systems with privileged access to critical services.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP Address | 46.30.191[.]230 | SpiceRAT server observed in the March 2026 cluster |
| IP Address | 188.190.29[.]126 | SpiceRAT infrastructure and cloned RTX page host |
| IP Address | 193.29.59[.]159 | SpiceRAT server observed in the March 2026 cluster |
| IP Address | 31.58.220[.]250 | SpiceRAT server observed in the March 2026 cluster |
| IP Address | 171.22.16[.]187 | SpiceRAT server observed in the March 2026 cluster |
| Domain | ns2.asiainfo.it[.]com | Hostname associated with SpiceRAT infrastructure |
| IP Address | 185.122.185[.]36 | Historical resolution for ns2.asiainfo.it[.]com |
| IP Address | 194.71.107[.]243 | Historical resolution for ns2.asiainfo.it[.]com |
| Domain | manager.skycom[.]support | SpiceRAT-related hostname |
| IP Address | 194.68.225[.]168 | Historical resolution for manager.skycom[.]support |
| IP Address | 194.14.217[.]119 | Historical resolution for manager.skycom[.]support |
| SHA-256 Hash | E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382 | Hash of the copied RTX Corporation web page |
| IP Address | 185.243.114[.]124 | Host serving the copied RTX page |
| Domain | www[.]tm-mfa[.]com | Domain observed on copied RTX page infrastructure |
| IP Address | 185.243.115[.]156 | Host serving the copied RTX page |
| IP Address | 45.153.125[.]200 | Reported SpiceRAT host serving the copied RTX page |
| IP Address | 194.68.44[.]133 | Reported SpiceRAT host serving the copied RTX page |
| Domain | infrastructure.minings[.]blog | Domain observed on copied RTX page infrastructure |
| IP Address | 2.58.14[.]95 | Hunt.io-detected SpiceRAT host |
| Domain | azure.uzrailwaystax[.]com | Spoofed Uzbek railway-themed domain |
| IP Address | 31.59.185[.]224 | Host serving the copied RTX page |
| Domain | ns.panterstationary[.]online | Domain observed on copied RTX page infrastructure |
| Domain | pro.taustas[.]com | Domain observed on copied RTX page infrastructure |
| IP Address | 2.58.15[.]172 | Host serving the copied RTX page |
| IP Address | 188.190.18[.]208 | Host serving copied RTX page and spoofed certificate |
| Domain | www.tmgaz-server[.]com | Domain impersonating Türkmengaz |
| IP Address | 46.30.188[.]54 | Host serving the copied RTX page |
| Domain | www.tojiktelecomtj[.]com | Domain impersonating Tojiktelecom |
| IP Address | 31.58.209[.]28 | Host serving the copied RTX page |
| Domain | infoxxe.plan-mail[.]com | Domain observed on copied RTX page infrastructure |
| Domain | mail.plan-mail[.]com | Domain observed on copied RTX page infrastructure |
| IP Address | 45.153.125[.]20 | Reported SpiceRAT host and certificate host |
| IP Address | 31.57.92[.]84 | Host serving the copied RTX page |
| IP Address | 185.243.114[.]238 | Host sharing the LokiDev self-signed certificate |
| Domain | normativ.dushanbeidc[.]org | Domain impersonating Tajikistan’s national IT hub project |
| IP Address | 92.243.66[.]71 | Host presenting the spoofed railway certificate |
| IP Address | 193.29.56[.]119 | Host presenting the spoofed railway certificate |
| IP Address | 193.29.57[.]182 | Host presenting the spoofed railway certificate |
| Domain | help.hoster-kg[.]com | Domain linked to NodeEdgeRAT registration activity |
| Domain | evo.hoster-kg[.]com | NodeEdgeRAT-related sibling hostname |
| Domain | uzrailway.devon-uz[.]com | BloodAlchemy-related railway-themed domain |
| SHA-256 Hash | 27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4 | SHA-256 fingerprint of the spoofed railway certificate |
| SHA-1 Hash | 9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39 | SHA-1 fingerprint of the spoofed railway certificate |
| JA4X Fingerprint | a373a9f83c6b_7022c563de38_4eebb5e6ba4e | JA4X fingerprint associated with the TLC-issued certificate |
| Certificate Serial | 81628176171941507003526847276457465393 | Serial number of the spoofed railway certificate |
| IP Address | 46.30.189[.]191 | Host associated with presidential-themed spoofing |
| Domain | state.presldent[.]info | Presidential-themed typosquatting domain |
| IP Address | 46.30.191[.]214 | Historical host for presidential-themed spoofing |
| Domain | cert.presldent[.]info | Presidential-themed typosquatting subdomain |
| IP Address | 45.86.163[.]87 | Historical host for presidential-themed spoofing |
| Domain | check.presldent[.]info | Presidential-themed typosquatting subdomain |
| IP Address | 2.58.15[.]101 | Historical host for presidential-themed spoofing |
| Domain | chief.presldent[.]info | Presidential-themed typosquatting subdomain |
| IP Address | 185.253.117[.]32 | Historical host for presidential-themed spoofing |
| Domain | it.presldent[.]info | Presidential-themed typosquatting subdomain |
| IP Address | 193.29.57[.]159 | Host associated with Uzbek telecom-themed spoofing |
| Domain | tmk.natcommunzu[.]com | Uzbekistan communications-themed domain |
| IP Address | 46.30.190[.]170 | Historical host for Uzbek telecom-themed spoofing |
| Domain | microsoft.natcommunzu[.]com | Subdomain under the communications-themed domain |
| IP Address | 185.243.112[.]253 | Historical SpiceRAT-related infrastructure host |
| Domain | storage.natcommunzu[.]com | Earliest related subdomain observed in July 2022 |
| IP Address | 185.243.112[.]220 | Historical infrastructure host |
| Domain | support.natcommunzu[.]com | Related communications-themed subdomain |
| IP Address | 45.67.230[.]185 | Historical infrastructure host |
| Domain | uz.natcommunzu[.]com | Related communications-themed subdomain |
| IP Address | 91.132.94[.]36 | Host associated with Central Asian energy-themed domains |
| Domain | help.galkynysh[.]net | Domain impersonating the Galkynysh gas field |
| Domain | kg.cwisuz[.]com | Domain observed on the same host |
| IP Address | 45.153.127[.]186 | Host associated with Kazakh government-themed spoofing |
| Domain | gov.mpekz[.]online | Kazakhstan government-themed domain |
| IP Address | 46.30.191[.]232 | Host associated with Tajikistan-themed spoofing |
| Domain | normativ.sozandagon[.]org | Tajikistan-themed domain |
| IP Address | 192.121.87[.]172 | Host associated with Kyrgyz presidential-themed spoofing |
| Domain | data.yntymak-ord[.]com | Kyrgyz presidential residence-themed domain |
| IP Address | 193.29.58[.]217 | Host associated with Kyrgyz presidential-themed spoofing |
| Domain | link.ytnymak-ord[.]com | Kyrgyz presidential residence-themed domain |
| IP Address | 195.88.191[.]70 | Host associated with Kyrgyz presidential-themed spoofing |
| Domain | center.yntymak-ordo[.]com | Kyrgyz presidential residence-themed domain |
| IP Address | 45.153.127[.]38 | Host associated with Uzbek administration-themed spoofing |
| Domain | azure.adm-devon[.]com | Uzbek administration-themed domain |
| IP Address | 5.183.95[.]49 | Host associated with Uzbek administration-themed spoofing |
| Domain | uz.adm-devon[.]com | Uzbek administration-themed domain |
| IP Address | 195.88.191[.]250 | Host associated with Turkmen energy-themed spoofing |
| Domain | sanly.oilgas-tm[.]com | Turkmen energy-themed domain |
| IP Address | 45.86.162[.]141 | Host with high-numbered remote desktop exposure |
| Domain | mail.postmfa[.]com | Foreign affairs-themed mail domain |
| IP Address | 45.153.127[.]99 | Host with high-numbered remote desktop exposure |
| Domain | center.infocomkg[.]org | Kyrgyzstan communications-themed domain |
| Domain | kg.tdtu[.]org | Domain sharing a parent domain with NomadRAT infrastructure |
| IP Address | 194.14.217[.]199 | Infrastructure host associated with Kyrgyzstan-themed spoofing |
| Domain | mail.infocomkg[.]org | Kyrgyzstan communications-themed mail domain |
| IP Address | 83.242.96[.]242 | Infrastructure host associated with Kyrgyzstan-themed spoofing |
| Domain | service.infocomkg[.]org | Kyrgyzstan communications-themed service domain |
| IP Address | 185.253.116[.]145 | Infrastructure host associated with related domains |
| Domain | info.tdtu[.]org | Related domain under the tdtu[.]org parent |
| IP Address | 193.29.59[.]248 | Infrastructure host associated with related domains |
| Domain | ud.tdtu[.]org | Related domain under the tdtu[.]org parent |
| IP Address | 5.183.95[.]7 | Host with high-numbered remote desktop exposure |
| Domain | api.hpsupporter[.]com | Support-themed infrastructure domain |
| IP Address | 46.30.191[.]90 | Infrastructure host associated with support-themed spoofing |
| Domain | checkup.hpsupporter[.]com | Support-themed infrastructure domain |
| IP Address | 2.58.15[.]129 | Infrastructure host associated with support-themed spoofing |
| Domain | help.hpsupporter[.]com | Support-themed infrastructure domain |
| IP Address | 45.86.162[.]249 | Infrastructure host associated with support-themed spoofing |
| Domain | telecom.hpsupporter[.]com | Support-themed telecommunications domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/silkparasite-linked-malware/