New Hunt.io research extends Bitdefender's SilkParasite report by connecting a SpiceRAT C2 cluster to NodeEdgeRAT and NomadRAT at the infrastructure level. A TLS certificate from TLC, a CA funded by a Chinese state research institute, impersonates Uzbekistan's railway and ties much of the cluster together.
The domains spoof named Central Asian government and energy entities, and passive DNS places the activity back to at least mid-2022. All network-side, no compromised hosts or samples.
Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Source: r/InfoSecNews · by /u/Straight-Practice-99
