Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
FBI Dismantles NightmareStresser DDoS Service
September 17, 2026
Critical BIND 9 Vulnerabilities Allow Cache Poisoning, DoS
September 17, 2026
CISA Urges Defenders to Deploy Deception Technologies
September 17, 2026
Home/CyberSecurity News/SilkParasite Malware Infrastructure Active for Four Years in Central Asia
CyberSecurity News

SilkParasite Malware Infrastructure Active for Four Years in Central Asia

Key Takeaways The SilkParasite cyberespionage campaign, previously thought to be recent, has been traced back four years in Central Asia. Attackers utilize spear-phishing with government-themed lures...

Jennifer sherman
Jennifer sherman
September 17, 2026 5 Min Read
3 0

Key Takeaways

  • The SilkParasite cyberespionage campaign, previously thought to be recent, has been traced back four years in Central Asia.
  • Attackers utilize spear-phishing with government-themed lures and legitimate Windows programs to deploy remote access malware like SpiceRAT, NodeEdgeRAT, and NomadRAT.
  • Targets include government entities, energy companies, and telecommunications providers across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan.
  • The campaign leverages shared infrastructure elements, including identical web page decoys and reused digital certificates, to maintain persistence and evade detection.
  • Attribution points to a potential China-nexus, though shared infrastructure alone does not definitively prove a direct operational link.

A sophisticated cyberespionage operation, dubbed SilkParasite, has been active in Central Asia for at least four years, targeting critical sectors such as government, energy, and telecommunications. Recent infrastructure analysis reveals that the scope and longevity of this campaign are far more extensive than initially understood, suggesting a persistent and well-resourced threat actor.

Table Of Content

  • Key Takeaways
  • Unearthing a Deeper Infrastructure
  • Connecting the Dots: Shared Artifacts
  • Central Asian Targets and Defense
  • What You Should Do

The attackers behind SilkParasite employ a multi-pronged approach, primarily relying on spear-phishing emails. These emails are meticulously crafted to appear legitimate, often containing convincing government-themed documents or masquerading as trusted Windows applications. Their objective is to infect victim systems with remote-access malware, establishing a foothold within targeted networks to facilitate data exfiltration and command execution.

Unearthing a Deeper Infrastructure

Analysts at Hunt.io, in collaboration with researcher Guy Yasur, meticulously uncovered a network of SpiceRAT command-and-control (C2) servers that were operational from late 2025 through August 2026. This discovery proved pivotal in linking previously disparate activities to the broader SilkParasite campaign.

In a detailed report shared with Cyber Security News (CSN), Hunt.io revealed that this infrastructure connects directly to SilkParasite. The campaign has been observed deploying at least seven distinct remote-access toolsets against government entities in Central Asian nations.

The significance of this finding lies not in a single malware sample, but in the intricate web of technical commonalities that tie together seemingly unrelated systems. By examining public-facing infrastructure, researchers gained valuable insights into how this long-running espionage operation constructs and reuses its technical assets. A more comprehensive analysis is available in this report.

Connecting the Dots: Shared Artifacts

The analysis revealed crucial technical overlaps that connected SpiceRAT servers to systems previously associated with NodeEdgeRAT and NomadRAT. These links included shared parent domains, identical digital certificates, and even a duplicated web page. While these connections don’t definitively attribute all hosts to a single operator, they strongly suggest either a unified operational entity or a shared support infrastructure.

Initial detection logic flagged SpiceRAT-related servers in late 2025. By March 2026, a cluster of five servers emerged across different providers and geographic locations within days of each other. The presence of shared hostnames and certificates provided a much stronger evidentiary link than individual malware detections, which only indicate activity on a single machine.

A key finding was the repeated use of an outdated, yet complete, copy of an RTX Corporation homepage. This decoy page, devoid of malicious code or credential forms, appeared on 13 distinct servers. Its consistent content hash provided researchers with a reliable method to map otherwise seemingly disconnected infrastructure, echoing patterns observed in other sophisticated remote access malware campaigns.

Further bolstering these links was the reuse of digital certificates. One particular certificate, designed to mimic an Uzbek railway entity, was found on eight different hosts, including those hosting the cloned RTX page. This certificate was issued by TLC, a certificate authority affiliated with a China state-linked communications research institute. It is important to note, however, that the issuer alone is not sufficient proof of malicious intent.

Passive DNS records pushed the timeline of this infrastructure even further back, revealing related subdomains active as early as mid-2022. This extends the operational period of the underlying infrastructure to at least four years, suggesting that “SilkParasite” may simply be a more recent designation for a long-running, persistent cyberespionage effort. More detailed information can be found in the full report.

Central Asian Targets and Defense

The attackers strategically employed domain names and hostnames designed to impersonate legitimate government agencies, national energy operators, and telecommunications organizations across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan. It is crucial to emphasize that these names indicate apparent impersonation targets, not confirmed breaches of the named organizations. Hunt.io confirmed that it notified affected organizations and relevant national CERTs prior to publishing their findings.

The targeting strategy aligns with the China-linked SilkParasite espionage campaign, which has been documented to use document lures and a combination of both well-known and newly identified remote access tools. While previous reports indicated a medium confidence in a China-nexus link, this new network evidence provides valuable context but does not, on its own, establish definitive attribution.

Researchers also identified naming conventions similar to infrastructure previously associated with suspected China-nexus activity, specifically the IndigoZebra and FamousSparrow campaigns. However, such overlaps can arise from shared toolsets, common service providers, or even widely adopted naming conventions. Therefore, these similarities serve as investigative leads rather than conclusive proof of a direct operational connection between these groups.

What You Should Do

  • Scan Network Logs: Proactively search your network logs, DNS records, and certificate data for the provided Indicators of Compromise (IoCs), especially if operating in the targeted sectors (government, energy, telecom).
  • Review Remote Desktop Exposure: Immediately investigate any unusual or unauthorized remote desktop exposure within your network.
  • Inspect Lookalike Domains: Promptly examine and verify any domains that closely resemble legitimate organizational or government websites.
  • Strengthen Phishing Defenses: Enhance your organization’s anti-phishing measures, including user training and email gateway protections.
  • Verify Documents Independently: Instruct employees to verify any unexpected government-themed documents through separate, trusted communication channels before opening them.
  • Restrict Remote Access: Implement stringent controls to restrict unnecessary remote access to internal systems and critical services.
  • Monitor for Artifacts: Continuously monitor for recurring web page or certificate artifacts that match those identified in the SilkParasite campaign.
  • Correlate Security Signals: Integrate and correlate signals from various security tools (endpoint detection, network logs, SIEM) to gain a comprehensive view of potential threats. This approach can help uncover staging and C2 systems that might evade standalone endpoint detections.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP Address 46.30.191[.]230 SpiceRAT server observed in the March 2026 cluster
IP Address 188.190.29[.]126 SpiceRAT infrastructure and cloned RTX page host
IP Address 193.29.59[.]159 SpiceRAT server observed in the March 2026 cluster
IP Address 31.58.220[.]250 SpiceRAT server observed in the March 2026 cluster
IP Address 171.22.16[.]187 SpiceRAT server observed in the March 2026 cluster
Domain ns2.asiainfo.it[.]com Hostname associated with SpiceRAT infrastructure
IP Address 185.122.185[.]36 Historical resolution for ns2.asiainfo.it[.]com
IP Address 194.71.107[.]243 Historical resolution for ns2.asiainfo.it[.]com
Domain manager.skycom[.]support SpiceRAT-related hostname
IP Address 194.68.225[.]168 Historical resolution for manager.skycom[.]support
IP Address 194.14.217[.]119 Historical resolution for manager.skycom[.]support
SHA-256 Hash E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382 Hash of the copied RTX Corporation web page
IP Address 185.243.114[.]124 Host serving the copied RTX page
Domain www[.]tm-mfa[.]com Domain observed on copied RTX page infrastructure
IP Address 185.243.115[.]156 Host serving the copied RTX page
IP Address 45.153.125[.]200 Reported SpiceRAT host serving the copied RTX page
IP Address 194.68.44[.]133 Reported SpiceRAT host serving the copied RTX page
Domain infrastructure.minings[.]blog Domain observed on copied RTX page infrastructure
IP Address 2.58.14[.]95 Hunt.io-detected SpiceRAT host
Domain azure.uzrailwaystax[.]com Spoofed Uzbek railway-themed domain
IP Address 31.59.185[.]224 Host serving the copied RTX page
Domain ns.panterstationary[.]online Domain observed on copied RTX page infrastructure
Domain pro.taustas[.]com Domain observed on copied RTX page infrastructure
IP Address 2.58.15[.]172 Host serving the copied RTX page
IP Address 188.190.18[.]208 Host serving copied RTX page and spoofed certificate
Domain www.tmgaz-server[.]com Domain impersonating Türkmengaz
IP Address 46.30.188[.]54 Host serving the copied RTX page
Domain www.tojiktelecomtj[.]com Domain impersonating Tojiktelecom
IP Address 31.58.209[.]28 Host serving the copied RTX page
Domain infoxxe.plan-mail[.]com Domain observed on copied RTX page infrastructure
Domain mail.plan-mail[.]com Domain observed on copied RTX page infrastructure
IP Address 45.153.125[.]20 Reported SpiceRAT host and certificate host
IP Address 31.57.92[.]84 Host serving the copied RTX page
IP Address 185.243.114[.]238 Host sharing the LokiDev self-signed certificate
Domain normativ.dushanbeidc[.]org Domain impersonating Tajikistan’s national IT hub project
IP Address 92.243.66[.]71 Host presenting the spoofed railway certificate
IP Address 193.29.56[.]119 Host presenting the spoofed railway certificate
IP Address 193.29.57[.]182 Host presenting the spoofed railway certificate
Domain help.hoster-kg[.]com Domain linked to NodeEdgeRAT registration activity
Domain evo.hoster-kg[.]com NodeEdgeRAT-related sibling hostname
Domain uzrailway.devon-uz[.]com BloodAlchemy-related railway-themed domain
SHA-256 Hash 27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4 SHA-256 fingerprint of the spoofed railway certificate
SHA-1 Hash 9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39 SHA-1 fingerprint of the spoofed railway certificate
JA4X Fingerprint a373a9f83c6b_7022c563de38_4eebb5e6ba4e JA4X fingerprint associated with the TLC-issued certificate
Certificate Serial 816281761

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

HEAVYGRAM Malware Uses Telegram as Command and Control Server

Next Post

CISA Urges Defenders to Deploy Deception Technologies

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Thai College Website Redirects Google Users to Illegal Online Casino
September 17, 2026
North Korean IT workers exploit AI, remote tools to fake interviews
September 17, 2026
Critical Docker Sandbox Vulnerabilities Let Guests Escape microVMs
September 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us