Hunt.io research team mapped a SpiceRAT C2 cluster and tied it to the SilkParasite campaign Bitdefender wrote up in August.
They found three malware families sharing infrastructure, a cloned Raytheon homepage reused as a decoy that exposed 13 servers from one page hash, and a TLS cert from a Chinese state-funded CA impersonating Uzbekistan's railway.
The targeting hits energy, government, and telecom across five Central Asian countries, and passive DNS puts the activity back to at least mid-2022. All from network-side data.
Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Source: r/pwnhub · by /u/Straight-Practice-99
