Hunt.io researchers tracked a SpiceRAT cluster and connect it back to the SilkParasite infrastructure Bitdefender published in August.
The main finding is that three families the report treated as distinct (SpiceRAT, NodeEdgeRAT, NomadRAT) share infrastructure at the registration and certificate level, which points to either one operator running multiple toolsets or a shared support function.
Scope: domains impersonating named government and energy entities across five Central Asian countries, including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's MFA. A TLS cert from TLC, a CA funded by a Chinese state research institute, ties much of it together.
Passive DNS dates the activity to at least mid-2022, so this reads as a longer and wider operation than the SilkParasite label suggests.
We also note overlaps with IndigoZebra (Speccom) alongside the report's FamousSparrow reference, both suspected China-nexus.
Full analysis, IOCs, and queries in the post:
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Source: r/threatintel · by /u/Straight-Practice-99