SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
Hunt.io links SpiceRAT C2 infrastructure to the China-nexus SilkParasite espionage cluster targeting Central Asian governments, telecoms, and energy firms.
Hunt.io analysis expanded the SpiceRAT command-and-control footprint tied to SilkParasite, a China-nexus espionage cluster (medium confidence per Bitdefender) targeting government, telecommunications, and energy entities across Central Asia. Five active servers coordinated from mid-March 2026 were clustered via reused hostnames, TLS certificates, and a byte-identical clone of RTX Corporation's webpage found on 13 IPs; a certificate for azure.uzrailwaystax[.]com appeared across eight servers. Domains impersonated Türkmengaz, Tojiktelecom, Turkmenistan's Foreign Ministry, and Uzbek and Kyrgyz bodies, with passive DNS history dating to mid-2022. Impersonated organizations were not confirmed as compromised; Cisco Talos previously linked SpiceRAT to SneakyChef's LNK/HTA infection chains.
- Five active SpiceRAT C2 servers emerged mid-March 2026 across European hosting networks
- TLS certificate for azure.uzrailwaystax[.]com appeared on eight servers, impersonating Uzbekistan's state railway
- Byte-identical RTX Corporation webpage clone found on 13 IPs, all tied to the cluster
- Hostnames pivot to NodeEdgeRAT and NomadRAT infrastructure, suggesting shared operators
- Defenders should hunt certificate fingerprints, page hashes, and RDP on high ports (64330-65535)
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | hoster-kg.com | NodeEdgeRAT and NomadRAT. A sibling domain associated with hoster-kg[.]com was listed by Bitdefender as NodeEdgeRAT infrastructure, |
| domain | hunt.io | ence data showing a SpiceRat detection on port 80 (Source : Hunt.io). Researchers found no credential collection forms, payload |
| domain | it.com | seller brands differ. A notable pivot involved ns2.asiainfo.it[.]com , which resolved to SpiceRAT servers in Estonia, Bulgaria |
| domain | skycom.support | and elsewhere during early 2026. Another hostname, manager.skycom[.]support , appeared in Bitdefender’s SilkParasite indicators and a |
| domain | tdtu.org | sted by Bitdefender as NodeEdgeRAT infrastructure, while kg.tdtu[.]org shared a parent-domain relationship with a NomadRAT C2 in |
| domain | uzrailwaystax.com | cant link. Multiple hosts presented a certificate for azure.uzrailwaystax[.]com , an attacker-controlled domain impersonating Uzbekistan’ |
| ipv4 | 185.122.185.36 | he SpiceRAT command channel operated separately over HTTPS. 185.122.185.36 IP intelligence data showing a SpiceRat detection on port 8 |
Full article940 words · extracted from gbhackers.com · click to collapse
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government, telecommunications, and energy-related entities across Central Asia.
The infrastructure findings extend the operational footprint around servers previously associated with the suspected China-nexus cluster, but do not establish that any impersonated organization was compromised.
Detection logic derived from Cisco Talos’ 2024 analysis of SpiceRAT first flagged related systems in late 2025, while a coordinated group of five active servers emerged in mid-March 2026.
Cisco previously linked SpiceRAT to the SneakyChef activity cluster, which targeted government organizations in EMEA and Asia using multi-stage infection chains initiated through LNK and HTA files.
The analysis centers on internet-facing infrastructure rather than malware delivery, victim telemetry, or initial access.
It identifies operational commonalities between servers through reused hostnames, TLS certificates, and an identical cloned webpage.
These artifacts provide stronger grounds for clustering than the mere presence of a common malware family, particularly where hosting providers, autonomous systems, and reseller brands differ.
A notable pivot involved ns2.asiainfo.it[.]com, which resolved to SpiceRAT servers in Estonia, Bulgaria, and elsewhere during early 2026.
Another hostname, manager.skycom[.]support, appeared in Bitdefender’s SilkParasite indicators and also resolved to previously unreported servers detected in January 2026.
Bitdefender’s August 19 SilkParasite report documented seven RAT families, including SpiceRAT, NodeEdgeRAT, NomadRAT, BloodAlchemy, and five newly named malware families.
It assessed the campaign as China-nexus with medium confidence, without attributing it to a specific established actor.
The infrastructure cluster also reused a static clone of RTX Corporation’s website as default web content.
A HuntSQL search for the copied page’s SHA-256 hash returned only 13 IP addresses, all associated exclusively with the examined cluster.
Research conducted jointly with Guy Yasur tracked SpiceRAT, servers active from late 2025 through August 2026 across a limited group of European hosting networks.
The same hostname resolves to two servers absent from BitDefender’s IoC list: 194.68.225[.]168 and 194.14.217[.]119, both detected in late January 2026, exposing ports 80 and 443.
The cloned site was served over HTTP, while the SpiceRAT command channel operated separately over HTTPS.

Researchers found no credential collection forms, payload delivery components, or malicious JavaScript on the RTX page, supporting the assessment that it functioned as a static decoy rather than an attack page.
SpiceRAT Infrastructure
Three of the 13 hosts were previously identified by Bitdefender as SpiceRAT C2 servers, while two additional hosts matched Hunt.io’s SpiceRAT detection signatures.
![RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source : Hunt.io).](https://public-hunt-static-blog-assets.s3.us-east-1.amazonaws.com/9-2026/Infrastructure+Analysis+of+the+SilkParasite+-+figure+2.png)
The remaining servers shared the exact webpage and recurring nginx versions, broadening the likely infrastructure footprint beyond published indicators.
This type of reusable web artifact is operationally valuable to defenders because a byte-identical page hash can reveal related systems even when domains, providers, and IP addresses rotate.
Several hosts in the cluster expose Remote Desktop on unusually high ports: 64350, 64330, 65535, and 65111. Querying for the above across the cluster’s primary ASNs surfaced additional infrastructure.
TLS certificate reuse produced another significant link. Multiple hosts presented a certificate for azure.uzrailwaystax[.]com, an attacker-controlled domain impersonating Uzbekistan’s state railway authority.

The same certificate appeared across eight servers, including hosts independently associated with SpiceRAT.
It was issued by TLC DV TLS CA, operated by TL Certification Center, which lists contact infrastructure under the CAICT domain; CAICT is affiliated with China’s Ministry of Industry and Information Technology.
The certificate issuer alone is not proof of attribution, but its use alongside the regional targeting pattern and shared server artifacts is a relevant investigative detail.
Registration-level pivots further connected the infrastructure to NodeEdgeRAT and NomadRAT. A sibling domain associated with hoster-kg[.]com was listed by Bitdefender as NodeEdgeRAT infrastructure, while kg.tdtu[.]org shared a parent-domain relationship with a NomadRAT C2 indicator.
These overlaps suggest either a common operator deploying multiple tools or infrastructure that is shared among closely aligned operators.
Observed domains impersonated entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, Turkmenistan’s Ministry of Foreign Affairs, Uzbek administrative bodies, and Kyrgyz government-related organizations.
Passive DNS history for related subdomains stretches back to mid-2022, indicating that portions of the infrastructure ecosystem may have existed for at least four years.
The named organizations should be treated strictly as apparent impersonation targets. The domains and certificates are attacker-controlled, and their appearance does not mean the organizations were breached.
Notifications issued where contact details were available likewise do not indicate review or confirmation by a recipient.
For defenders in Central Asian government, energy, and telecom environments, the key detection opportunities are certificate fingerprints, repeated default-page hashes, suspicious government-themed typosquats, reused parent domains, and unusual RDP-over-TLS exposure on high-numbered ports.
The infrastructure evidence reinforces Bitdefender’s conclusion that SilkParasite represents a persistent, modular espionage operation focused on strategically important regional institutions.
Indicators of Compromise
| IP | Hostname | Ports | AS Name | Reseller | Country | First Seen |
|---|---|---|---|---|---|---|
| 46.30.191[.]230 | – | 80, 443 | GWY IT PTY LTD | CrownCloud | NL | 2026-02-09 |
| 188.190.29[.]126 | ns2.asiainfo.it[.]com | 80 | EDIS GmbH | – | BG | 2026-02-26 |
| 193.29.59[.]159 | – | 80, 443 | IP-Project | CrownCloud | DE | 2026-03-02 |
| 31.58.220[.]250 | – | 443 | AS56971 Cloud | CloudBackbone | NL | 2026-03-04 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/spicerat-infrastructure/