Skip to main content

🕵️ Hunting SilkParasite / SpiceRAT infrastructure by page hash, TLS cert, and RDP-over-TLS on high ports

0
High
Published: 09/16/2026 (09/16/2026, 17:06:07 UTC)
Source: Reddit BlueTeam

Description

This report details the infrastructure of SpiceRAT malware linked to the SilkParasite campaign targeting government and energy sectors across Central Asia. The infrastructure includes a cluster of command and control servers active from late 2025 through mid-2026, identified by shared TLS certificates, reused hostnames, and identical cloned web pages. The attackers impersonate legitimate entities such as Uzbekistan's state railway authority using TLS certificates issued by a Chinese state-affiliated CA. The infrastructure spans multiple hosting providers and countries, with evidence of ongoing activity for at least four years. The report provides detection indicators including IPs, domains, TLS certs, and page hashes for defenders to conduct retro hunts. No direct malware behavior or initial access vectors are covered in this analysis.

Reddit Discussion

r/blueteamsec·posted by u/Straight-Practice-99
00

Detection-focused writeup on a SpiceRAT C2 cluster connected to Bitdefender's SilkParasite report. Everything here is reproducible from scan data.

Hunting hooks: a reused decoy page collapses to one SHA-256 body hash across 13 hosts; a TLC-issued cert (subject azure.uzrailwaystax[.]com, SHA-256 in the post) sits on 8 hosts; hardened RDP on unusual high ports (64350, 64330, 65535, 65111) shows up under a tls fingerprint rather than RDP, so filter for that. Two nginx versions (1.29.3 and 1.31.3) recur across the fleet.

Full IOC tables (IPs, domains, cert fields, subdomain and passive DNS history) plus the HuntSQL queries are in the post, ready for retro hunts.

https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 14:17:20 UTC

Technical Analysis

Researchers tracked a cluster of SpiceRAT command and control servers active from late 2025 to August 2026, linked to the SilkParasite campaign targeting Central Asian government and energy sectors. The infrastructure is identified by shared artifacts: a TLS certificate impersonating Uzbekistan's railway authority issued by a Chinese state-affiliated CA, reused hostnames resolving to multiple servers across different countries, and a cloned RTX Corporation homepage serving as a decoy page with a unique SHA-256 hash found on 13 hosts. The cluster overlaps with infrastructure attributed by Bitdefender to multiple malware families including SpiceRAT, NodeEdgeRAT, and NomadRAT. Passive DNS data indicates the infrastructure has been active since at least mid-2022. The report focuses on detection and infrastructure analysis using internet-wide scan data and does not address malware delivery or behavior.

Potential Impact

The infrastructure supports command and control operations for multiple malware families, enabling persistent remote access and control over targeted networks in government and energy sectors in Central Asia. The use of legitimate-appearing TLS certificates and cloned web pages aids in evading detection and impersonating trusted entities. While no direct compromise of the named organizations is confirmed, the infrastructure facilitates ongoing espionage and cyber operations against sensitive sectors.

Defensive Guidance

No direct remediation or patch is applicable as this is an adversary infrastructure report rather than a software vulnerability. Defenders should leverage the provided indicators of compromise—such as the specific TLS certificate details, the unique SHA-256 hash of the cloned webpage, and the unusual RDP-over-TLS high ports (e.g., 64350, 64330, 65535, 65111)—to detect and block related network activity. Retroactive network hunts using the HuntSQL queries and IOC tables shared in the report are recommended to identify potential compromises. There is no indication that the targeted organizations are compromised or that immediate action beyond detection and monitoring is required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aabf65f55bf5e2cf57b2f45

Added to database: 09/17/2026, 14:17:03 UTC

Last enriched: 09/17/2026, 14:17:20 UTC

Last updated: 09/18/2026, 00:31:35 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses