Skip to content
DnsLister Forum

Where domain hunters compare notes

🚩 Suspected China-nexus SpiceRAT hits Central Asian government and energy

New Hunt.io research extends Bitdefender's SilkParasite report by connecting a SpiceRAT C2 cluster to NodeEdgeRAT and NomadRAT at the infrastructure level. A TLS certificate from TLC, a CA funded by a Chinese state research institute, impersonates Uzbekistan's railway and ties much of the cluster together.

The domains spoof named Central Asian government and energy entities, and passive DNS places the activity back to at least mid-2022. All network-side, no compromised hosts or samples.

Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

Source: r/InfoSecNews · by /u/Straight-Practice-99

Leave a Reply

Your email address will not be published. Required fields are marked *