securityaffairs.com 17 Sept 2026, 14:16 UTC

SilkParasite Linked to RAT Infrastructure Targeting Central Asia

SilkParasite Linked to RAT Infrastructure Targeting Central Asia
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
🇨🇳 SilkParasite

HUNT .io and researcher Guy Yasur have mapped infrastructure linking the SpiceRAT, NodeEdgeRAT and NomadRAT malware families to the SilkParasite campaign, which has targeted governments and critical sectors in Central Asia. Their analysis, published on 17 September 2026, focused on command-and-control infrastructure rather than malware samples and extends Bitdefender’s August 2026 research.

Five SpiceRAT servers identified in March 2026 were connected through common hostnames, TLS certificates and a cloned default webpage, despite being hosted by different providers and in different countries.

One certificate impersonated Uzbekistan’s state railway authority through the domain azure.uzrailwaystax[.]com. It was issued by TLC DV TLS CA, a certificate authority wholly funded by CAICT, a Chinese state research institute; Hunt.io cautioned that the issuer alone is not an indicator of malicious activity. A server at 188.190.29[.]126 also served a byte-for-byte copy of RTX Corporation’s homepage.

A HuntSQL search for that page’s SHA-256 hash found 13 hosts: three already associated with SpiceRAT by Bitdefender, two matching Hunt.io’s SpiceRAT signature and eight linked through shared nginx versions and the same page.

The researchers found domains impersonating ministries and state enterprises in Turkmenistan, Uzbekistan, Tajikistan and Kyrgyzstan, with passive DNS suggesting activity dating back to mid-2022. They said the links indicate shared infrastructure or tooling, but do not prove a single operator or settle attribution.

Hunt.io recommends that organisations in the region, particularly government, telecoms and OT/ICS networks, check for the published indicators, including the RTX page hash, railway-themed certificate, spoofed domains and high-numbered RDP-over-TLS ports 64350, 64330, 65535 and 65111.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline