SilkParasite Campaign Extends SpiceRAT Infrastructure Targeting Central Asian Governments and Energy Firms
Researchers at Hunt.io, working with Guy Yasur, identified a cluster of
Shared certificates and hostnames extend the confirmed SpiceRAT footprint from five servers to at least twenty-one hosts, narrowing the value of sample-based detection against this cluster. A TLC-issued certificate ties a Chinese state-funded certification authority to infrastructure spoofing Uzbekistan's railway authority, narrowing the field of plausible operators despite the CA's otherwise unremarkable customer base, though the shared RTX webpage template could equally reflect a common hosting reseller across unrelated operators rather than one coordinated campaign. Passive DNS pushing the operation's roots to 2022 reframes SilkParasite as a rebrand of a four-year-old effort, and links NodeEdgeRAT and NomadRAT to the cluster via certificates rather than malware samples, a shift from Bitdefender's August sample-based attribution. Coverage rests on a single Hunt.io investigation amplified by other outlets rather than independently verified, leaving unlisted infrastructure across the same five Central Asian countries unmapped for defenders relying on signatures alone.
4 sources
- SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia -
Hunt.io - SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets -
Security Affairs - SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia -
Cyber Security News - SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms -
GBHackers