ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

SilkParasite-Linked SpiceRAT Infrastructure Traced Back to 2022 in China-Nexus Espionage Targeting Central Asia

highThreat actorexploited in the wildimportance 60
What's new: First merged summary for this story: Hunt.io expanded the SpiceRAT C2 footprint attributed to SilkParasite, documenting five active servers coordinated from mid-March 2026, extending the infrastructure timeline to mid-2022 via passive DNS, and linking SpiceRAT systems to NodeEdgeRAT and NomadRAT infrastructure through shared domains, certificates and a cloned RTX webpage.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Hunt.io links SpiceRAT command-and-control servers to the China-nexus SilkParasite espionage cluster via shared certificates and a cloned RTX webpage, connecting them to NodeEdgeRAT and NomadRAT infrastructure with passive DNS history dating to mid-2022 and…

Hunt.io and researcher Guy Yasur traced a cluster of SpiceRAT command-and-control servers — active from late 2025 to August 2026, with five active servers coordinated from mid-March 2026 across European hosting networks — to infrastructure linked to SilkParasite, a China-nexus espionage cluster (medium confidence per Bitdefender) targeting government, telecommunications and energy entities across Central Asia. The clustering rests on shared parent domains, reused hostnames and TLS certificates, a certificate for azure.uzrailwaystax[.]com impersonating Uzbekistan's state railway that appeared on eight servers, and a byte-identical clone of RTX Corporation's webpage found on 13 IPs tied to the cluster. Shared hostnames pivot to NodeEdgeRAT and NomadRAT infrastructure, suggesting shared operators. Passive DNS records date the related infrastructure to mid-2022, suggesting SilkParasite is a newer label for an effort at least four years old. Impersonated hostnames target organizations in Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan, including Türkmengaz, Tojiktelecom and Turkmenistan's Foreign Ministry, though the impersonated organizations were not confirmed as compromised. Cisco Talos previously linked SpiceRAT to SneakyChef's LNK/HTA infection chains. Defenders are advised to hunt published IoCs — certificate fingerprints, page hashes and DNS records — and restrict remote-access exposure, including RDP on high ports 64330-65535.

  • Hunt.io and researcher Guy Yasur tied SpiceRAT C2 servers to SilkParasite, a China-nexus espionage cluster (medium confidence per Bitdefender) targeting government, telecom and energy entities in Central Asia.
  • Five active SpiceRAT C2 servers were coordinated from mid-March 2026 across European hosting networks; overall SpiceRAT server activity traced from late 2025 to August 2026.
  • A TLS certificate for azure.uzrailwaystax[.]com, impersonating Uzbekistan's state railway, appeared across eight servers.
  • A byte-identical clone of RTX Corporation's webpage was found on 13 IPs, all tied to the cluster.
  • Shared hostnames pivot to NodeEdgeRAT and NomadRAT infrastructure, suggesting shared operators.
  • Passive DNS history dates to mid-2022, suggesting SilkParasite is a newer label for infrastructure at least four years old.
  • Impersonated hostnames target government, energy and telecom organizations in Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan, including Türkmengaz, Tojiktelecom and Turkmenistan's Foreign Ministry; those organizations were…
  • Cisco Talos previously linked SpiceRAT to SneakyChef's LNK/HTA infection chains.

Coverage timeline

  1. · 1h ago
    Cyber Security News· 60
    SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia

    Hunt.io links SpiceRAT C2 servers to China-nexus SilkParasite espionage targeting Central Asian governments, with related infrastructure active since 2022.

  2. · 1h ago
    GBHackers· 55
    SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms

    Hunt.io links SpiceRAT C2 infrastructure to the China-nexus SilkParasite espionage cluster targeting Central Asian governments, telecoms, and energy firms.