Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

SilkParasite: Uncovering the Web of Intrigue Behind Central Asian Cyberattacks




The SilkParasite infrastructure links SpiceRAT to Central Asian targets, with the use of shared certificates and domains providing a powerful tool for defenders. This campaign targets ministries and state enterprises across five Central Asian countries, dating back to at least mid-2022. Organizations in the affected sectors and regions can use the indicators and observations outlined in this report to assess their own exposure to this threat.

  • The SilkParasite infrastructure links SpiceRAT to Central Asian targets, marking a complex and multifaceted campaign.
  • R researchers at Hunt.io identified five SpiceRAT command-and-control servers linked through shared elements, including hostnames, TLS certificates, and a cloned webpage.
  • A Chinese state research institute may be behind the procurement of a certificate impersonating a Central Asian state entity.
  • A reused webpage on a cluster of SpiceRAT servers serves as a powerful fingerprint for identifying connected servers.
  • The SilkParasite campaign targets ministries and state enterprises across five Central Asian countries, with a wider and longer footprint than initially thought.



  • The world of cyberattacks has long been a complex and multifaceted landscape, with new threats emerging every day. In recent months, a particularly insidious campaign has been making waves, with the SilkParasite infrastructure linking SpiceRAT to Central Asian targets. This article delves into the intricacies of this campaign, exploring the methods used to link the SpiceRAT command-and-control servers, the use of shared certificates and domains, and the implications for organizations in the region.

    In March 2026, researchers at Hunt.io identified five SpiceRAT command-and-control servers hosted by different providers and in different countries. These servers were linked through several common elements, including the same hostnames, TLS certificates, and a cloned webpage used as the default page. This approach looks at the infrastructure behind the malware, rather than focusing solely on the malware itself, and provides a powerful tool for defenders to identify other servers linked to the campaign.

    One certificate in particular stands out - it impersonates Uzbekistan's state railway authority (azure.uzrailwaystax[.]com) and was issued by TLC DV TLS CA, a CA wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology. This domain-validated cert spoofing a Central Asian state entity from a China-based CA does suggest a deliberate procurement channel.

    Requests to ns2.asiainfo.it[.]com on 188.190.29[.]126 returned a full copy of RTX Corporation's homepage, complete with navigation, subsidiary links, and a stock ticker. The page contained no malicious code and wasn't unique to that server, but its reuse across the cluster made it a powerful fingerprint.

    Hunt.io's C2 Infrastructure module tracks servers matching detection signatures for known malware families, including SpiceRAT. In mid-March 2026, they observed a cluster of five active SpiceRAT servers, each active together across multiple hosting providers and countries. A HuntSQL query on the page's SHA-256 hash returned exactly 13 hosts, three of which were already in Bitdefender's SpiceRAT list, two more matched Hunt.io's SpiceRAT signature, and the remaining eight extended the footprint through shared nginx versions and the same static page.

    The report concludes that the targeting picture that emerges from this infrastructure, named ministries and state enterprises across five Central Asian countries dating back to at least mid-2022, suggests SilkParasite is a more recent label for an operation with much longer and wider footprint. Organizations in the affected sectors and regions can make use of the above indicators and observations to assess their own exposure.

    This article aims to provide a comprehensive overview of the SilkParasite campaign, exploring the methods used to link the SpiceRAT command-and-control servers, the use of shared certificates and domains, and the implications for organizations in the region. By understanding the intricacies of this campaign, defenders can better prepare themselves to defend against future threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/SilkParasite-Uncovering-the-Web-of-Intrigue-Behind-Central-Asian-Cyberattacks-ehn.shtml

  • https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html


  • Published: Thu Sep 17 14:01:10 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us