Skip to content
DnsLister Forum

Where domain hunters compare notes

🚩 Suspected China-nexus SpiceRAT hits Central Asian government and energy

Hunt.io research team mapped a SpiceRAT C2 cluster and tied it to the SilkParasite campaign Bitdefender wrote up in August.

They found three malware families sharing infrastructure, a cloned Raytheon homepage reused as a decoy that exposed 13 servers from one page hash, and a TLS cert from a Chinese state-funded CA impersonating Uzbekistan's railway.

The targeting hits energy, government, and telecom across five Central Asian countries, and passive DNS puts the activity back to at least mid-2022. All from network-side data.

Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

Source: r/pwnhub · by /u/Straight-Practice-99

Leave a Reply

Your email address will not be published. Required fields are marked *