Skip to content
DnsLister Forum

Where domain hunters compare notes

🐁 SpiceRAT infrastructure targets government and energy across Central Asia

Researchers tie SpiceRAT servers to energy and government targets across Central Asia, extending Bitdefender's SilkParasite report

New research from Hunt.io on a SpiceRAT command and control cluster that connects to the SilkParasite infrastructure Bitdefender reported last month.

The short version: three malware families that were treated as separate (SpiceRAT, NodeEdgeRAT, NomadRAT) share infrastructure at the registration and certificate level.

A TLS certificate from a Chinese state-funded CA, impersonating Uzbekistan's state railway, ties much of it together. The domains spoof named government and energy entities across five Central Asian countries, and passive DNS dates the activity back to at least mid-2022.

All of it was reconstructed from internet scan data, without touching a compromised host.

Full report: https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

Source: r/cybersecurity · by /u/Straight-Practice-99

Leave a Reply

Your email address will not be published. Required fields are marked *