🕵️ Hunting SilkParasite / SpiceRAT infrastructure by page hash, TLS cert, and RDP-over-TLS on high ports
This report details the infrastructure of SpiceRAT malware linked to the SilkParasite campaign targeting government and energy sectors across Central Asia. The infrastructure includes a cluster of command and control servers active from late 2025 through mid-2026, identified by shared TLS certificates, reused hostnames, and identical cloned web pages. The attackers impersonate legitimate entities such as Uzbekistan's state railway authority using TLS certificates issued by a Chinese state-affiliated CA. The infrastructure spans multiple hosting providers and countries, with evidence of ongoing activity for at least four years. The report provides detection indicators including IPs, domains, TLS certs, and page hashes for defenders to conduct retro hunts. No direct malware behavior or initial access vectors are covered in this analysis.
AI Analysis
Technical Summary
Researchers tracked a cluster of SpiceRAT command and control servers active from late 2025 to August 2026, linked to the SilkParasite campaign targeting Central Asian government and energy sectors. The infrastructure is identified by shared artifacts: a TLS certificate impersonating Uzbekistan's railway authority issued by a Chinese state-affiliated CA, reused hostnames resolving to multiple servers across different countries, and a cloned RTX Corporation homepage serving as a decoy page with a unique SHA-256 hash found on 13 hosts. The cluster overlaps with infrastructure attributed by Bitdefender to multiple malware families including SpiceRAT, NodeEdgeRAT, and NomadRAT. Passive DNS data indicates the infrastructure has been active since at least mid-2022. The report focuses on detection and infrastructure analysis using internet-wide scan data and does not address malware delivery or behavior.
Potential Impact
The infrastructure supports command and control operations for multiple malware families, enabling persistent remote access and control over targeted networks in government and energy sectors in Central Asia. The use of legitimate-appearing TLS certificates and cloned web pages aids in evading detection and impersonating trusted entities. While no direct compromise of the named organizations is confirmed, the infrastructure facilitates ongoing espionage and cyber operations against sensitive sectors.
Mitigation Recommendations
No direct remediation or patch is applicable as this is an adversary infrastructure report rather than a software vulnerability. Defenders should leverage the provided indicators of compromise—such as the specific TLS certificate details, the unique SHA-256 hash of the cloned webpage, and the unusual RDP-over-TLS high ports (e.g., 64350, 64330, 65535, 65111)—to detect and block related network activity. Retroactive network hunts using the HuntSQL queries and IOC tables shared in the report are recommended to identify potential compromises. There is no indication that the targeted organizations are compromised or that immediate action beyond detection and monitoring is required.
🕵️ Hunting SilkParasite / SpiceRAT infrastructure by page hash, TLS cert, and RDP-over-TLS on high ports
Description
This report details the infrastructure of SpiceRAT malware linked to the SilkParasite campaign targeting government and energy sectors across Central Asia. The infrastructure includes a cluster of command and control servers active from late 2025 through mid-2026, identified by shared TLS certificates, reused hostnames, and identical cloned web pages. The attackers impersonate legitimate entities such as Uzbekistan's state railway authority using TLS certificates issued by a Chinese state-affiliated CA. The infrastructure spans multiple hosting providers and countries, with evidence of ongoing activity for at least four years. The report provides detection indicators including IPs, domains, TLS certs, and page hashes for defenders to conduct retro hunts. No direct malware behavior or initial access vectors are covered in this analysis.
Reddit Discussion
Detection-focused writeup on a SpiceRAT C2 cluster connected to Bitdefender's SilkParasite report. Everything here is reproducible from scan data.
Hunting hooks: a reused decoy page collapses to one SHA-256 body hash across 13 hosts; a TLC-issued cert (subject azure.uzrailwaystax[.]com, SHA-256 in the post) sits on 8 hosts; hardened RDP on unusual high ports (64350, 64330, 65535, 65111) shows up under a tls fingerprint rather than RDP, so filter for that. Two nginx versions (1.29.3 and 1.31.3) recur across the fleet.
Full IOC tables (IPs, domains, cert fields, subdomain and passive DNS history) plus the HuntSQL queries are in the post, ready for retro hunts.
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers tracked a cluster of SpiceRAT command and control servers active from late 2025 to August 2026, linked to the SilkParasite campaign targeting Central Asian government and energy sectors. The infrastructure is identified by shared artifacts: a TLS certificate impersonating Uzbekistan's railway authority issued by a Chinese state-affiliated CA, reused hostnames resolving to multiple servers across different countries, and a cloned RTX Corporation homepage serving as a decoy page with a unique SHA-256 hash found on 13 hosts. The cluster overlaps with infrastructure attributed by Bitdefender to multiple malware families including SpiceRAT, NodeEdgeRAT, and NomadRAT. Passive DNS data indicates the infrastructure has been active since at least mid-2022. The report focuses on detection and infrastructure analysis using internet-wide scan data and does not address malware delivery or behavior.
Potential Impact
The infrastructure supports command and control operations for multiple malware families, enabling persistent remote access and control over targeted networks in government and energy sectors in Central Asia. The use of legitimate-appearing TLS certificates and cloned web pages aids in evading detection and impersonating trusted entities. While no direct compromise of the named organizations is confirmed, the infrastructure facilitates ongoing espionage and cyber operations against sensitive sectors.
Defensive Guidance
No direct remediation or patch is applicable as this is an adversary infrastructure report rather than a software vulnerability. Defenders should leverage the provided indicators of compromise—such as the specific TLS certificate details, the unique SHA-256 hash of the cloned webpage, and the unusual RDP-over-TLS high ports (e.g., 64350, 64330, 65535, 65111)—to detect and block related network activity. Retroactive network hunts using the HuntSQL queries and IOC tables shared in the report are recommended to identify potential compromises. There is no indication that the targeted organizations are compromised or that immediate action beyond detection and monitoring is required.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aabf65f55bf5e2cf57b2f45
Added to database: 09/17/2026, 14:17:03 UTC
Last enriched: 09/17/2026, 14:17:20 UTC
Last updated: 09/18/2026, 00:31:35 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.