A cyber-espionage network dubbed SilkParasite—targeting government, telecom, and energy sectors across Central Asia—has been found to have a far older and wider infrastructure than previously understood. Recent analysis reveals that command-and-control (C2) systems used by malware families tied to this operation, including SpiceRAT, NodeEdgeRAT, and NomadRAT, have roots tracing back at least to mid-2022 and appear across multiple countries and malware toolsets.
Shared Hosts, Certificates & Decoy Sites: Threads Between RAT Families
Researchers with Hunt.io and independent security analyst Guy Yasur have identified commonalities between servers attributed to SpiceRAT and those linked to NodeEdgeRAT and NomadRAT. These artifacts include shared parent domains, reused digital certificates, and identical decoy web content—namely a cloned, outdated version of RTX Corporation’s homepage served across 13 different IP addresses.
One particular TLS certificate impersonating Uzbekistan’s state railway authority, issued by TLC—a Chinese state‐affiliated certificate authority—was found deployed on eight hosts. Four of those hosted the cloned RTX page as well. Additionally, domains mimicking state energy firms, ministries of foreign affairs, and telecommunications bodies in Turkmenistan, Uzbekistan, Tajikistan, Kyrgyzstan, and Kazakhstan are being used extensively.
Longer Running Than Expected & Multitool Operation
Passive DNS data pushes the observed infrastructure’s lifespan back to at least 2022—revealing that SilkParasite may be a recent label for an operations complex in place for years. The overlapping use of infrastructure across multiple malware families suggests either a single operator owning several toolsets, or a shared support network used by multiple actors.
The malware toolset uncovered in Bitdefender’s SilkParasite report includes seven remote access tools (RATs): SpiceRAT and BloodAlchemy (earlier known tools), plus five newly documented ones—DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Different malware components reuse the same infrastructure elements—such as certificates and domains—across families.
Attack delivery typically begins with regionally customized spear-phishing. Victims receive password-protected archives masquerading as government documents; opening them launches malicious Office macros that initiate DLL sideloading—a legitimate binary being tricked into loading malicious code.
Other noteworthy signals include code artifacts often seen in AI-assisted development workflows. For example, some tools contain literal placeholder values like “0123456789abcdef” in encryption keys, or test functions leftover in production builds. These anomalies hint at partial adoption of automated or assisted coding in the malware’s development.
Security teams are being urged to scan for unusual remote‐access endpoints, lookalike government domains, and reused web content—especially the cloned RTX page—and to monitor certificate reuse. Indicators of compromise (IoCs) published include IPs, domains, and certificate hashes tied to the campaign.
Though attributions have been made with medium confidence to a China-linked espionage nexus, the evidence remains circumstantial. Shared infrastructure, domain spoofing, and code similarities suggest links to China-nexus actors such as FamousSparrow and IndigoZebra, but researchers emphasize that shared tool use or conventions do not equal direct control.
What this means: SilkParasite isn’t just a new threat—it’s a long-running campaign that’s been refining its espionage tools, infrastructure, and targeting for years. The reuse of infrastructure across malware families blurs the lines between separate threat actors, complicating attribution and detection efforts. Continuous monitoring of certificates, hostnames, and domain spoofing—along with strengthening phishing defenses—is essential. What to watch for next: whether this infrastructure will expand its targeting beyond Central Asia, or if defenders can disrupt shared assets (like impersonated domains or reused certs) to break the operation’s linkage.