SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity behind the campaign may be older and broader than its recent name suggests.

The operation has used spear-phishing emails carrying convincing government-themed documents and trusted Windows programs to plant remote-access malware. These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.

Hunt.io analysts, working with researcher Guy Yasur, identified a connected group of SpiceRAT command-and-control servers active from late 2025 to August 2026.

Hunt.io said in a report shared with Cyber Security News (CSN) that the infrastructure links to SilkParasite, which used seven remote-access toolsets against Central Asian governments.

The discovery matters because it joins seemingly separate systems through repeated technical traces rather than one malware sample. Public-facing infrastructure can reveal how a long-running spying operation builds and reuses its systems.

SilkParasite-Linked Malware Infrastructure

The shared parent domains, a matching digital certificate and a copied web page connect SpiceRAT servers to systems attributed to NodeEdgeRAT and NomadRAT. This does not prove one operator controls every host, but suggests a common operation or shared support function.

Analysts first flagged SpiceRAT-related servers in late 2025 using earlier detection logic. In March 2026, five servers appeared within days across different providers and countries. Shared hostnames and certificates were stronger links, because a detection only shows what ran on one machine.

One recurring decoy was a complete but outdated copy of an RTX Corporation homepage. The page contained no malicious code, credential form or delivery mechanism.

Yet its identical content hash appeared on 13 servers and gave researchers a reliable way to map infrastructure that otherwise looked unrelated, much like patterns seen in remote access malware operations.

Certificate reuse strengthened the link. A certificate made to resemble an Uzbek railway entity appeared on eight hosts, including systems carrying the cloned page.

Screenshot of the RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source - Hunt.io)
Screenshot of the RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source – Hunt.io)

The certificate was issued by TLC, a certificate authority operated by an organization funded by China’s state-linked communications research institute, although the issuer alone is not an indicator of malicious activity.

Passive DNS records extended the timeline further. Related subdomains were seen as early as mid-2022, suggesting the infrastructure has existed for at least four years. This suggests SilkParasite may be a newer label for a longer-running effort.

Central Asian Targets and Defense

The infrastructure used names resembling government agencies, state energy operators and telecom organizations across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.

These names should be treated as apparent impersonation targets, not evidence that the named organizations were breached. Hunt.io said it notified affected organizations and relevant national CERTs before publication.

The targeting overlaps with China-linked SilkParasite espionage campaign, which used document lures and a mix of established and newly documented remote-access tools.

That report assessed a China-nexus link with medium confidence. The newer network evidence offers useful context, but it does not independently establish attribution.

Researchers also noted naming similarities with infrastructure previously tied to suspected China-nexus activity known as IndigoZebra, as well as overlaps cited with FamousSparrow.

Such patterns can result from shared tools, service providers or conventions, so they are leads for investigation rather than proof of a direct operational relationship.

For defenders, the practical lesson is to search network logs, DNS records and certificate data for the indicators published below, especially in the affected sectors.

Teams should review unusual remote desktop exposure and investigate lookalike domains promptly. Recent cases involving malware abusing developer tunnels show why outbound connections and remote-management paths deserve continuous scrutiny.

Organizations should also strengthen phishing defenses, verify unexpected government-themed documents through separate channels, restrict unnecessary remote access and monitor for repeated web-page or certificate artifacts.

Correlating those signals can expose staging and command systems that may not be caught by endpoint detections alone, giving incident responders a broader picture of potential exposure. This includes systems with privileged access to critical services.

Indicators of compromise (IoCs):-

Type Indicator Description
IP Address 46.30.191[.]230 SpiceRAT server observed in the March 2026 cluster
IP Address 188.190.29[.]126 SpiceRAT infrastructure and cloned RTX page host
IP Address 193.29.59[.]159 SpiceRAT server observed in the March 2026 cluster
IP Address 31.58.220[.]250 SpiceRAT server observed in the March 2026 cluster
IP Address 171.22.16[.]187 SpiceRAT server observed in the March 2026 cluster
Domain ns2.asiainfo.it[.]com Hostname associated with SpiceRAT infrastructure
IP Address 185.122.185[.]36 Historical resolution for ns2.asiainfo.it[.]com
IP Address 194.71.107[.]243 Historical resolution for ns2.asiainfo.it[.]com
Domain manager.skycom[.]support SpiceRAT-related hostname
IP Address 194.68.225[.]168 Historical resolution for manager.skycom[.]support
IP Address 194.14.217[.]119 Historical resolution for manager.skycom[.]support
SHA-256 Hash E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382 Hash of the copied RTX Corporation web page
IP Address 185.243.114[.]124 Host serving the copied RTX page
Domain www[.]tm-mfa[.]com Domain observed on copied RTX page infrastructure
IP Address 185.243.115[.]156 Host serving the copied RTX page
IP Address 45.153.125[.]200 Reported SpiceRAT host serving the copied RTX page
IP Address 194.68.44[.]133 Reported SpiceRAT host serving the copied RTX page
Domain infrastructure.minings[.]blog Domain observed on copied RTX page infrastructure
IP Address 2.58.14[.]95 Hunt.io-detected SpiceRAT host
Domain azure.uzrailwaystax[.]com Spoofed Uzbek railway-themed domain
IP Address 31.59.185[.]224 Host serving the copied RTX page
Domain ns.panterstationary[.]online Domain observed on copied RTX page infrastructure
Domain pro.taustas[.]com Domain observed on copied RTX page infrastructure
IP Address 2.58.15[.]172 Host serving the copied RTX page
IP Address 188.190.18[.]208 Host serving copied RTX page and spoofed certificate
Domain www.tmgaz-server[.]com Domain impersonating Türkmengaz
IP Address 46.30.188[.]54 Host serving the copied RTX page
Domain www.tojiktelecomtj[.]com Domain impersonating Tojiktelecom
IP Address 31.58.209[.]28 Host serving the copied RTX page
Domain infoxxe.plan-mail[.]com Domain observed on copied RTX page infrastructure
Domain mail.plan-mail[.]com Domain observed on copied RTX page infrastructure
IP Address 45.153.125[.]20 Reported SpiceRAT host and certificate host
IP Address 31.57.92[.]84 Host serving the copied RTX page
IP Address 185.243.114[.]238 Host sharing the LokiDev self-signed certificate
Domain normativ.dushanbeidc[.]org Domain impersonating Tajikistan’s national IT hub project
IP Address 92.243.66[.]71 Host presenting the spoofed railway certificate
IP Address 193.29.56[.]119 Host presenting the spoofed railway certificate
IP Address 193.29.57[.]182 Host presenting the spoofed railway certificate
Domain help.hoster-kg[.]com Domain linked to NodeEdgeRAT registration activity
Domain evo.hoster-kg[.]com NodeEdgeRAT-related sibling hostname
Domain uzrailway.devon-uz[.]com BloodAlchemy-related railway-themed domain
SHA-256 Hash 27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4 SHA-256 fingerprint of the spoofed railway certificate
SHA-1 Hash 9297D5FD21EF21B16F5880CD4FAEA2AD1FB9EE39 SHA-1 fingerprint of the spoofed railway certificate
JA4X Fingerprint a373a9f83c6b_7022c563de38_4eebb5e6ba4e JA4X fingerprint associated with the TLC-issued certificate
Certificate Serial 81628176171941507003526847276457465393 Serial number of the spoofed railway certificate
IP Address 46.30.189[.]191 Host associated with presidential-themed spoofing
Domain state.presldent[.]info Presidential-themed typosquatting domain
IP Address 46.30.191[.]214 Historical host for presidential-themed spoofing
Domain cert.presldent[.]info Presidential-themed typosquatting subdomain
IP Address 45.86.163[.]87 Historical host for presidential-themed spoofing
Domain check.presldent[.]info Presidential-themed typosquatting subdomain
IP Address 2.58.15[.]101 Historical host for presidential-themed spoofing
Domain chief.presldent[.]info Presidential-themed typosquatting subdomain
IP Address 185.253.117[.]32 Historical host for presidential-themed spoofing
Domain it.presldent[.]info Presidential-themed typosquatting subdomain
IP Address 193.29.57[.]159 Host associated with Uzbek telecom-themed spoofing
Domain tmk.natcommunzu[.]com Uzbekistan communications-themed domain
IP Address 46.30.190[.]170 Historical host for Uzbek telecom-themed spoofing
Domain microsoft.natcommunzu[.]com Subdomain under the communications-themed domain
IP Address 185.243.112[.]253 Historical SpiceRAT-related infrastructure host
Domain storage.natcommunzu[.]com Earliest related subdomain observed in July 2022
IP Address 185.243.112[.]220 Historical infrastructure host
Domain support.natcommunzu[.]com Related communications-themed subdomain
IP Address 45.67.230[.]185 Historical infrastructure host
Domain uz.natcommunzu[.]com Related communications-themed subdomain
IP Address 91.132.94[.]36 Host associated with Central Asian energy-themed domains
Domain help.galkynysh[.]net Domain impersonating the Galkynysh gas field
Domain kg.cwisuz[.]com Domain observed on the same host
IP Address 45.153.127[.]186 Host associated with Kazakh government-themed spoofing
Domain gov.mpekz[.]online Kazakhstan government-themed domain
IP Address 46.30.191[.]232 Host associated with Tajikistan-themed spoofing
Domain normativ.sozandagon[.]org Tajikistan-themed domain
IP Address 192.121.87[.]172 Host associated with Kyrgyz presidential-themed spoofing
Domain data.yntymak-ord[.]com Kyrgyz presidential residence-themed domain
IP Address 193.29.58[.]217 Host associated with Kyrgyz presidential-themed spoofing
Domain link.ytnymak-ord[.]com Kyrgyz presidential residence-themed domain
IP Address 195.88.191[.]70 Host associated with Kyrgyz presidential-themed spoofing
Domain center.yntymak-ordo[.]com Kyrgyz presidential residence-themed domain
IP Address 45.153.127[.]38 Host associated with Uzbek administration-themed spoofing
Domain azure.adm-devon[.]com Uzbek administration-themed domain
IP Address 5.183.95[.]49 Host associated with Uzbek administration-themed spoofing
Domain uz.adm-devon[.]com Uzbek administration-themed domain
IP Address 195.88.191[.]250 Host associated with Turkmen energy-themed spoofing
Domain sanly.oilgas-tm[.]com Turkmen energy-themed domain
IP Address 45.86.162[.]141 Host with high-numbered remote desktop exposure
Domain mail.postmfa[.]com Foreign affairs-themed mail domain
IP Address 45.153.127[.]99 Host with high-numbered remote desktop exposure
Domain center.infocomkg[.]org Kyrgyzstan communications-themed domain
Domain kg.tdtu[.]org Domain sharing a parent domain with NomadRAT infrastructure
IP Address 194.14.217[.]199 Infrastructure host associated with Kyrgyzstan-themed spoofing
Domain mail.infocomkg[.]org Kyrgyzstan communications-themed mail domain
IP Address 83.242.96[.]242 Infrastructure host associated with Kyrgyzstan-themed spoofing
Domain service.infocomkg[.]org Kyrgyzstan communications-themed service domain
IP Address 185.253.116[.]145 Infrastructure host associated with related domains
Domain info.tdtu[.]org Related domain under the tdtu[.]org parent
IP Address 193.29.59[.]248 Infrastructure host associated with related domains
Domain ud.tdtu[.]org Related domain under the tdtu[.]org parent
IP Address 5.183.95[.]7 Host with high-numbered remote desktop exposure
Domain api.hpsupporter[.]com Support-themed infrastructure domain
IP Address 46.30.191[.]90 Infrastructure host associated with support-themed spoofing
Domain checkup.hpsupporter[.]com Support-themed infrastructure domain
IP Address 2.58.15[.]129 Infrastructure host associated with support-themed spoofing
Domain help.hpsupporter[.]com Support-themed infrastructure domain
IP Address 45.86.162[.]249 Infrastructure host associated with support-themed spoofing
Domain telecom.hpsupporter[.]com Support-themed telecommunications domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia appeared first on Cyber Security News.