Researchers tie SpiceRAT servers to energy and government targets across Central Asia, extending Bitdefender's SilkParasite report
New research from Hunt.io on a SpiceRAT command and control cluster that connects to the SilkParasite infrastructure Bitdefender reported last month.
The short version: three malware families that were treated as separate (SpiceRAT, NodeEdgeRAT, NomadRAT) share infrastructure at the registration and certificate level.
A TLS certificate from a Chinese state-funded CA, impersonating Uzbekistan's state railway, ties much of it together. The domains spoof named government and energy entities across five Central Asian countries, and passive DNS dates the activity back to at least mid-2022.
All of it was reconstructed from internet scan data, without touching a compromised host.
Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Source: r/cybersecurity · by /u/Straight-Practice-99
