Hunt.io tracked a SpiceRAT command and control cluster and connected it to Bitdefender's SilkParasite report, linking SpiceRAT, NodeEdgeRAT, and NomadRAT through shared infrastructure and a common TLS certificate from a Chinese state-funded CA.
Targets span government and energy entities across five Central Asian countries, with passive DNS dating the operation back to at least mid-2022. Reconstructed entirely from scan data.
Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Source: r/NowInCyber · by /u/Straight-Practice-99
