SilkParasite Malware Infrastructure Active for Four Years in Central Asia
Key Takeaways The SilkParasite cyberespionage campaign, previously thought to be recent, has been traced back four years in Central Asia. Attackers utilize spear-phishing with government-themed lures...
Key Takeaways
- The SilkParasite cyberespionage campaign, previously thought to be recent, has been traced back four years in Central Asia.
- Attackers utilize spear-phishing with government-themed lures and legitimate Windows programs to deploy remote access malware like SpiceRAT, NodeEdgeRAT, and NomadRAT.
- Targets include government entities, energy companies, and telecommunications providers across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan.
- The campaign leverages shared infrastructure elements, including identical web page decoys and reused digital certificates, to maintain persistence and evade detection.
- Attribution points to a potential China-nexus, though shared infrastructure alone does not definitively prove a direct operational link.
A sophisticated cyberespionage operation, dubbed SilkParasite, has been active in Central Asia for at least four years, targeting critical sectors such as government, energy, and telecommunications. Recent infrastructure analysis reveals that the scope and longevity of this campaign are far more extensive than initially understood, suggesting a persistent and well-resourced threat actor.
Table Of Content
The attackers behind SilkParasite employ a multi-pronged approach, primarily relying on spear-phishing emails. These emails are meticulously crafted to appear legitimate, often containing convincing government-themed documents or masquerading as trusted Windows applications. Their objective is to infect victim systems with remote-access malware, establishing a foothold within targeted networks to facilitate data exfiltration and command execution.
Unearthing a Deeper Infrastructure
Analysts at Hunt.io, in collaboration with researcher Guy Yasur, meticulously uncovered a network of SpiceRAT command-and-control (C2) servers that were operational from late 2025 through August 2026. This discovery proved pivotal in linking previously disparate activities to the broader SilkParasite campaign.
In a detailed report shared with Cyber Security News (CSN), Hunt.io revealed that this infrastructure connects directly to SilkParasite. The campaign has been observed deploying at least seven distinct remote-access toolsets against government entities in Central Asian nations.
The significance of this finding lies not in a single malware sample, but in the intricate web of technical commonalities that tie together seemingly unrelated systems. By examining public-facing infrastructure, researchers gained valuable insights into how this long-running espionage operation constructs and reuses its technical assets. A more comprehensive analysis is available in this report.
Connecting the Dots: Shared Artifacts
The analysis revealed crucial technical overlaps that connected SpiceRAT servers to systems previously associated with NodeEdgeRAT and NomadRAT. These links included shared parent domains, identical digital certificates, and even a duplicated web page. While these connections don’t definitively attribute all hosts to a single operator, they strongly suggest either a unified operational entity or a shared support infrastructure.
Initial detection logic flagged SpiceRAT-related servers in late 2025. By March 2026, a cluster of five servers emerged across different providers and geographic locations within days of each other. The presence of shared hostnames and certificates provided a much stronger evidentiary link than individual malware detections, which only indicate activity on a single machine.
A key finding was the repeated use of an outdated, yet complete, copy of an RTX Corporation homepage. This decoy page, devoid of malicious code or credential forms, appeared on 13 distinct servers. Its consistent content hash provided researchers with a reliable method to map otherwise seemingly disconnected infrastructure, echoing patterns observed in other sophisticated remote access malware campaigns.
Further bolstering these links was the reuse of digital certificates. One particular certificate, designed to mimic an Uzbek railway entity, was found on eight different hosts, including those hosting the cloned RTX page. This certificate was issued by TLC, a certificate authority affiliated with a China state-linked communications research institute. It is important to note, however, that the issuer alone is not sufficient proof of malicious intent.
Passive DNS records pushed the timeline of this infrastructure even further back, revealing related subdomains active as early as mid-2022. This extends the operational period of the underlying infrastructure to at least four years, suggesting that “SilkParasite” may simply be a more recent designation for a long-running, persistent cyberespionage effort. More detailed information can be found in the full report.
Central Asian Targets and Defense
The attackers strategically employed domain names and hostnames designed to impersonate legitimate government agencies, national energy operators, and telecommunications organizations across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan. It is crucial to emphasize that these names indicate apparent impersonation targets, not confirmed breaches of the named organizations. Hunt.io confirmed that it notified affected organizations and relevant national CERTs prior to publishing their findings.
The targeting strategy aligns with the China-linked SilkParasite espionage campaign, which has been documented to use document lures and a combination of both well-known and newly identified remote access tools. While previous reports indicated a medium confidence in a China-nexus link, this new network evidence provides valuable context but does not, on its own, establish definitive attribution.
Researchers also identified naming conventions similar to infrastructure previously associated with suspected China-nexus activity, specifically the IndigoZebra and FamousSparrow campaigns. However, such overlaps can arise from shared toolsets, common service providers, or even widely adopted naming conventions. Therefore, these similarities serve as investigative leads rather than conclusive proof of a direct operational connection between these groups.
What You Should Do
- Scan Network Logs: Proactively search your network logs, DNS records, and certificate data for the provided Indicators of Compromise (IoCs), especially if operating in the targeted sectors (government, energy, telecom).
- Review Remote Desktop Exposure: Immediately investigate any unusual or unauthorized remote desktop exposure within your network.
- Inspect Lookalike Domains: Promptly examine and verify any domains that closely resemble legitimate organizational or government websites.
- Strengthen Phishing Defenses: Enhance your organization’s anti-phishing measures, including user training and email gateway protections.
- Verify Documents Independently: Instruct employees to verify any unexpected government-themed documents through separate, trusted communication channels before opening them.
- Restrict Remote Access: Implement stringent controls to restrict unnecessary remote access to internal systems and critical services.
- Monitor for Artifacts: Continuously monitor for recurring web page or certificate artifacts that match those identified in the SilkParasite campaign.
- Correlate Security Signals: Integrate and correlate signals from various security tools (endpoint detection, network logs, SIEM) to gain a comprehensive view of potential threats. This approach can help uncover staging and C2 systems that might evade standalone endpoint detections.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP Address | 46.30.191[.]230 |
SpiceRAT server observed in the March 2026 cluster |
| IP Address | 188.190.29[.]126 |
SpiceRAT infrastructure and cloned RTX page host |
| IP Address | 193.29.59[.]159 |
SpiceRAT server observed in the March 2026 cluster |
| IP Address | 31.58.220[.]250 |
SpiceRAT server observed in the March 2026 cluster |
| IP Address | 171.22.16[.]187 |
SpiceRAT server observed in the March 2026 cluster |
| Domain | ns2.asiainfo.it[.]com |
Hostname associated with SpiceRAT infrastructure |
| IP Address | 185.122.185[.]36 |
Historical resolution for ns2.asiainfo.it[.]com |
| IP Address | 194.71.107[.]243 |
Historical resolution for ns2.asiainfo.it[.]com |
| Domain | manager.skycom[.]support |
SpiceRAT-related hostname |
| IP Address | 194.68.225[.]168 |
Historical resolution for manager.skycom[.]support |
| IP Address | 194.14.217[.]119 |
Historical resolution for manager.skycom[.]support |
| SHA-256 Hash | E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382 |
Hash of the copied RTX Corporation web page |
| IP Address | 185.243.114[.]124 |
Host serving the copied RTX page |
| Domain | www[.]tm-mfa[.]com |
Domain observed on copied RTX page infrastructure |
| IP Address | 185.243.115[.]156 |
Host serving the copied RTX page |
| IP Address | 45.153.125[.]200 |
Reported SpiceRAT host serving the copied RTX page |
| IP Address | 194.68.44[.]133 |
Reported SpiceRAT host serving the copied RTX page |
| Domain | infrastructure.minings[.]blog |
Domain observed on copied RTX page infrastructure |
| IP Address | 2.58.14[.]95 |
Hunt.io-detected SpiceRAT host |
| Domain | azure.uzrailwaystax[.]com |
Spoofed Uzbek railway-themed domain |
| IP Address | 31.59.185[.]224 |
Host serving the copied RTX page |
| Domain | ns.panterstationary[.]online |
Domain observed on copied RTX page infrastructure |
| Domain | pro.taustas[.]com |
Domain observed on copied RTX page infrastructure |
| IP Address | 2.58.15[.]172 |
Host serving the copied RTX page |
| IP Address | 188.190.18[.]208 |
Host serving copied RTX page and spoofed certificate |
| Domain | www.tmgaz-server[.]com |
Domain impersonating Türkmengaz |
| IP Address | 46.30.188[.]54 |
Host serving the copied RTX page |
| Domain | www.tojiktelecomtj[.]com |
Domain impersonating Tojiktelecom |
| IP Address | 31.58.209[.]28 |
Host serving the copied RTX page |
| Domain | infoxxe.plan-mail[.]com |
Domain observed on copied RTX page infrastructure |
| Domain | mail.plan-mail[.]com |
Domain observed on copied RTX page infrastructure |
| IP Address | 45.153.125[.]20 |
Reported SpiceRAT host and certificate host |
| IP Address | 31.57.92[.]84 |
Host serving the copied RTX page |
| IP Address | 185.243.114[.]238 |
Host sharing the LokiDev self-signed certificate |
| Domain | normativ.dushanbeidc[.]org |
Domain impersonating Tajikistan’s national IT hub project |
| IP Address | 92.243.66[.]71 |
Host presenting the spoofed railway certificate |
| IP Address | 193.29.56[.]119 |
Host presenting the spoofed railway certificate |
| IP Address | 193.29.57[.]182 |
Host presenting the spoofed railway certificate |
| Domain | help.hoster-kg[.]com |
Domain linked to NodeEdgeRAT registration activity |
| Domain | evo.hoster-kg[.]com |
NodeEdgeRAT-related sibling hostname |
| Domain | uzrailway.devon-uz[.]com |
BloodAlchemy-related railway-themed domain |
| SHA-256 Hash | 27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4 |
SHA-256 fingerprint of the spoofed railway certificate |
| SHA-1 Hash | 9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39 |
SHA-1 fingerprint of the spoofed railway certificate |
| JA4X Fingerprint | a373a9f83c6b_7022c563de38_4eebb5e6ba4e |
JA4X fingerprint associated with the TLC-issued certificate |
| Certificate Serial | 816281761
|



No Comment! Be the first one.