IC Technology & Cyber — 2026-09-20

SilkParasite Campaign Extends SpiceRAT Infrastructure Targeting Central Asian Governments and Energy Firms

BLUFInfrastructure artifact reuse across this four-year Chinese-linked espionage cluster exposes a detection gap that Central Asian defenders relying on malware signatures alone cannot close.

Researchers at Hunt.io, working with Guy Yasur, identified a cluster of SpiceRAT command-and-control servers active from late 2025 through August 2026, tied by shared hostnames, TLS certificates, and a cloned RTX Corporation webpage found on 13 hosts 1. A certificate impersonating Uzbekistan's state railway authority appeared on eight of those servers and was issued by TLC, a certificate authority funded by China's state-linked CAICT research institute 12. Hunt.io reports that shared parent domains and certificates connect this infrastructure to hosts Bitdefender attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT, three of seven malware families documented in its August 19 SilkParasite report, and that passive DNS records trace related subdomains to at least mid-2022 13. Identified domains impersonate government, energy, and telecom entities in Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan, and Hunt.io states it notified affected organizations and national CERTs before publication 123. GBHackers notes the findings extend the infrastructure footprint without establishing that any impersonated organization was compromised 4.

Analysis
Shared certificates and hostnames extend the confirmed SpiceRAT footprint from five servers to at least twenty-one hosts, narrowing the value of sample-based detection against this cluster. A TLC-issued certificate ties a Chinese state-funded certification authority to infrastructure spoofing Uzbekistan's railway authority, narrowing the field of plausible operators despite the CA's otherwise unremarkable customer base, though the shared RTX webpage template could equally reflect a common hosting reseller across unrelated operators rather than one coordinated campaign. Passive DNS pushing the operation's roots to 2022 reframes SilkParasite as a rebrand of a four-year-old effort, and links NodeEdgeRAT and NomadRAT to the cluster via certificates rather than malware samples, a shift from Bitdefender's August sample-based attribution. Coverage rests on a single Hunt.io investigation amplified by other outlets rather than independently verified, leaving unlisted infrastructure across the same five Central Asian countries unmapped for defenders relying on signatures alone.
4 sources
  1. SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia - Hunt.io
  2. SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets - Security Affairs
  3. SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia - Cyber Security News
  4. SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE