Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the operation with enough precision to tie three of SilkParasite’s seven RAT families (SpiceRAT, NodeEdgeRAT, and NomadRAT) through shared certificates, domains, and hosting patterns.
“Shared parent domains and an identical TLS certificate connect this infrastructure to hosts Bitdefender attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT, three of the seven malware families documented in the SilkParasite report.” reads the report published by Hunt.io.
“The certificate imitating the Uzbekistan railway entity was issued by TLC, a certificate authority wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology.”
In March 2026, Hunt.io identified five SpiceRAT command-and-control servers hosted by different providers and in different countries. Researchers linked them through several common elements, including the same hostnames, TLS certificates, and a cloned webpage used as the default page.
Instead of focusing only on the malware itself, this approach looks at the infrastructure behind it. Shared certificates or identical webpage hashes can provide strong and practical indicators that defenders can use to identify other servers linked to the campaign.
One certificate in particular stands out. It impersonates Uzbekistan’s state railway authority (azure.uzrailwaystax[.]com) and was issued by TLC DV TLS CA, a CA wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology. The issuer alone isn’t an indicator—nearly 3,000 servers host TLC certificates—but a domain‑validated cert spoofing a Central Asian state entity from a China‑based CA does suggest a deliberate procurement channel.
Requests to ns2.asiainfo.it[.]com on 188.190.29[.]126 returned a full copy of RTX Corporation’s homepage, complete with navigation, subsidiary links, and a stock ticker. The page contained no malicious code and wasn’t unique to that server, but its reuse across the cluster made it a powerful fingerprint.
“Hunt.io’s C2 Infrastructure module tracks servers matching detection signatures for known malware families, including SpiceRAT. In mid-March 2026, we observed a cluster of five active SpiceRAT servers: 46.30.191[.]230, 188.190.29[.]126, 193.29.59[.]159, 31.58.220[.]250, and 171.22.16[.]187. The five were active together in mid-March 2026, across multiple hosting providers and countries.” continues the report.
A HuntSQL query on the page’s SHA‑256 hash returned exactly 13 hosts; three were already in Bitdefender’s SpiceRAT list, two more matched Hunt.io’s SpiceRAT signature, and the remaining eight extended the footprint through shared nginx versions and the same static page.
Why RTX? The report offers two plausible explanations: the page rendered cleanly and was grabbed as a convenient template, or it reflects shared tooling where the clone functions as a default deployment asset. Either way, for defenders it’s a low‑noise, high‑precision signature: byte‑for‑byte identical wherever it lands.
Bitdefender’s SilkParasite report treated several RAT families as distinct, but Hunt.io’s network view shows they share parent domains and certificates. For example, help.hoster‑kg[.]com (on 193.29.58[.]192) presented the same railway‑spoofing certificate, while Bitdefender attributed evo.hoster‑kg[.]com to NodeEdgeRAT; the two are linked through shared registration of hoster‑kg[.]com, not a shared server. Similarly, kg.tdtu[.]org shares a parent domain with mineconom.tdtu[.]org, a NomadRAT C2 indicator in the SilkParasite report.
This doesn’t prove a single operator, but it does show a support function or toolset shared across the campaign. From a detection standpoint, it means pivoting on domains, certificates, and hosting profiles can surface nodes that sample‑based analysis would miss.
The cluster’s domains don’t just look governmental; they spoof specific ministries and state enterprises. Examples include help.galkynysh[.]net (Galkynysh gas field, Turkmenistan), tmgaz‑server[.]com (Türkmengaz), tm‑mfa[.]com (Turkmenistan’s Ministry of Foreign Affairs), and tojiktelecomtj[.]com (Tojiktelecom, Tajikistan). Additional domains impersonate Turkmen energy (sanly.oilgas‑tm[.]com), Uzbek administration (azure.adm‑devon[.]com), and even the Kyrgyz president’s residence (data.yntymak‑ordo[.]com).
Bitdefender’s targeting came from lures and infection telemetry; Hunt.io’s infrastructure analysis names the same sectors with concrete entities. Passive DNS and subdomain enumeration push the timeline back to mid‑2022, suggesting this isn’t a new campaign with a fresh brand—it’s a longer‑running operation now labeled SilkParasite.
SilkParasite overlaps with FamousSparrow, a suspected China‑nexus actor previously seen targeting hotels, governments, and international organizations. The infrastructure also mirrors IndigoZebra (Speccom), documented by Check Point in 2021 as targeting Central Asian ministries with similar domain patterns (mail, service, help) and overlapping naming conventions. These parallels don’t settle attribution, but they do reinforce a consistent operational style across China‑nexus activity in Central Asia.
If you’re responsible for OT/ICS, telecom, or government networks in the region, start by checking your edge and DMZ for the indicators below, especially the RTX page hash and the railway‑spoofing certificate. Monitor for high‑numbered RDP‑over‑TLS ports (64350, 64330, 65535, 65111) on the ASNs most prevalent in the cluster, and watch for domains impersonating local hosting providers or state entities. The original Hunt.io post includes the full IoC tables and HuntSQL queries; linking to it is essential for precise awareness and for teams that want to reproduce the pivots.
“The targeting picture that emerges from this infrastructure, named ministries and state enterprises across five Central Asian countries dating back to at least mid-2022 suggests SilkParasite is a more recent label for an operation with much longer and wider footprint.” concludes the report. “Organizations in the affected sectors and regions can make use of the above indicators and observations to assess their own exposure.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, SilkParasite)
