SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia
Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...
AI Analysis
Technical Summary
This threat involves a sophisticated cluster of command and control servers linked to the SpiceRAT malware family and related RATs such as NodeEdgeRAT, NomadRAT, and BloodAlchemy. The infrastructure is characterized by shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage, indicating coordinated management or shared resources. A notable aspect is the use of a TLS certificate impersonating Uzbekistan's railway authority issued by a Chinese state-affiliated certificate authority, facilitating spoofing of Central Asian government and energy sector domains. Passive DNS analysis reveals the infrastructure has been active since mid-2022, with recent activity continuing through August 2026. The infrastructure overlaps with tactics and infrastructure used by known China-associated threat actors FamousSparrow and IndigoZebra, suggesting a possible state-affiliated campaign targeting Central Asian government and energy sectors. This is an ongoing espionage infrastructure rather than a software vulnerability or exploit.
Potential Impact
The infrastructure supports multiple remote access trojans (RATs) used to target government and energy sector entities in Central Asia, potentially enabling espionage, data exfiltration, and network compromise. The use of spoofed domains and TLS certificates increases the likelihood of successful deception and evasion of detection. The prolonged operational period (at least four years) indicates sustained targeting and potential compromise of sensitive organizations. There are no known exploits or vulnerabilities in software products directly associated with this infrastructure.
Mitigation Recommendations
This is an active threat infrastructure rather than a software vulnerability; therefore, no patches or software fixes apply. Defenders should monitor for indicators of compromise related to the identified RAT families and spoofed domains. Network defenders should validate TLS certificates and domain authenticity, especially those impersonating government and critical infrastructure entities. Organizations in Central Asia should be particularly vigilant for spear-phishing and other intrusion attempts linked to these threat actors. No vendor advisories or official fixes are applicable.
Indicators of Compromise
- domain: post.mfa-uz.com
- domain: kginfocom.com
- domain: natcommunzu.com
- ip: 46.30.188.54
- ip: 45.67.230.185
- ip: 2.58.14.95
- ip: 193.29.59.248
- ip: 185.243.112.253
- ip: 185.122.185.36
- ip: 46.30.191.230
- ip: 193.29.59.159
- ip: 31.58.220.250
- domain: www.wordcheck.info
- ip: 171.22.16.187
- domain: api.hpsupporter.com
- domain: help.hpsupporter.com
- domain: checkup.hpsupporter.com
- domain: uzrailway.devon-uz.com
- ip: 5.183.95.7
- domain: tm-mfa.com
- domain: evo.hoster-kg.com
- domain: hoster-kg.com
- ip: 193.29.58.192
- domain: help.hoster-kg.com
- domain: infrastructure.minings.blog
- domain: kg.cwisuz.com
- domain: manager.skycom.support
- domain: mineconom.tdtu.org
- hash: 9297d5fd21ef21b16f5880cd4faea2ad1fb9ee39
- hash: 27e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4
- hash: e9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382
- ip: 185.243.112.220
- ip: 185.243.114.124
- ip: 185.243.114.238
- ip: 185.243.115.156
- ip: 188.190.18.208
- ip: 188.243.115.156
- ip: 193.29.56.119
- ip: 193.29.57.159
- ip: 193.29.57.182
- ip: 193.29.58.217
- ip: 195.88.191.250
- ip: 195.88.191.70
- ip: 2.58.14.91
- ip: 2.58.15.101
- ip: 2.58.15.129
- ip: 2.58.15.172
- ip: 31.57.92.84
- ip: 31.58.209.28
- ip: 31.59.185.224
- ip: 45.86.162.141
- ip: 45.86.162.249
- ip: 45.86.163.87
- ip: 46.30.189.191
- ip: 46.30.190.170
- ip: 46.30.191.214
- ip: 46.30.191.232
- ip: 46.30.191.90
- ip: 5.183.95.49
- ip: 83.242.96.242
- ip: 88.190.1.208
- domain: infocomkg.org
- domain: tmgaz-server.com
- domain: tojiktelecomtj.com
- domain: azure.adm-devon.com
- domain: azure.uzrailwaystax.com
- domain: center.infocomkg.org
- domain: center.yntymak-ordo.com
- domain: cert.presldent.info
- domain: check.presldent.info
- domain: chief.presldent.info
- domain: data.yntymak-ord.com
- domain: data.yntymak-ordo.com
- domain: gov.mpekz.online
- domain: help.galkynysh.net
- domain: info.tdtu.org
- domain: infoxxe.plan-mail.com
- domain: it.presldent.info
- domain: kg.tdtu.org
- domain: link.ytnymak-ord.com
- domain: mail.infocomkg.org
- domain: mail.plan-mail.com
- domain: mail.postmfa.com
- domain: microsoft.natcommunzu.com
- domain: normativ.dushanbeidc.org
- domain: normativ.sozandagon.org
- domain: ns.panterstationary.online
- domain: ns1.wordcheck.info
- domain: pro.taustas.com
- domain: sanly.oilgas-tm.com
- domain: service.infocomkg.org
- domain: state.presldent.info
- domain: storage.natcommunzu.com
- domain: support.natcommunzu.com
- domain: telecom.hpsupporter.com
- domain: tmk.natcommunzu.com
- domain: ud.tdtu.org
- domain: uz.adm-devon.com
- domain: uz.natcommunzu.com
- domain: www.tm-mfa.com
- domain: www.tmgaz-server.com
- domain: www.tojiktelecomtj.com
SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia
Description
Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a sophisticated cluster of command and control servers linked to the SpiceRAT malware family and related RATs such as NodeEdgeRAT, NomadRAT, and BloodAlchemy. The infrastructure is characterized by shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage, indicating coordinated management or shared resources. A notable aspect is the use of a TLS certificate impersonating Uzbekistan's railway authority issued by a Chinese state-affiliated certificate authority, facilitating spoofing of Central Asian government and energy sector domains. Passive DNS analysis reveals the infrastructure has been active since mid-2022, with recent activity continuing through August 2026. The infrastructure overlaps with tactics and infrastructure used by known China-associated threat actors FamousSparrow and IndigoZebra, suggesting a possible state-affiliated campaign targeting Central Asian government and energy sectors. This is an ongoing espionage infrastructure rather than a software vulnerability or exploit.
Potential Impact
The infrastructure supports multiple remote access trojans (RATs) used to target government and energy sector entities in Central Asia, potentially enabling espionage, data exfiltration, and network compromise. The use of spoofed domains and TLS certificates increases the likelihood of successful deception and evasion of detection. The prolonged operational period (at least four years) indicates sustained targeting and potential compromise of sensitive organizations. There are no known exploits or vulnerabilities in software products directly associated with this infrastructure.
Defensive Guidance
This is an active threat infrastructure rather than a software vulnerability; therefore, no patches or software fixes apply. Defenders should monitor for indicators of compromise related to the identified RAT families and spoofed domains. Network defenders should validate TLS certificates and domain authenticity, especially those impersonating government and critical infrastructure entities. Organizations in Central Asia should be particularly vigilant for spear-phishing and other intrusion attempts linked to these threat actors. No vendor advisories or official fixes are applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure"]
- Adversary
- SilkParasite
- Pulse Id
- 6aaacff0ea056cea51165b6b
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainpost.mfa-uz.com | — | |
domainkginfocom.com | — | |
domainnatcommunzu.com | — | |
domainwww.wordcheck.info | — | |
domainapi.hpsupporter.com | — | |
domainhelp.hpsupporter.com | — | |
domaincheckup.hpsupporter.com | — | |
domainuzrailway.devon-uz.com | — | |
domaintm-mfa.com | — | |
domainevo.hoster-kg.com | — | |
domainhoster-kg.com | — | |
domainhelp.hoster-kg.com | — | |
domaininfrastructure.minings.blog | — | |
domainkg.cwisuz.com | — | |
domainmanager.skycom.support | — | |
domainmineconom.tdtu.org | — | |
domaininfocomkg.org | — | |
domaintmgaz-server.com | — | |
domaintojiktelecomtj.com | — | |
domainazure.adm-devon.com | — | |
domainazure.uzrailwaystax.com | — | |
domaincenter.infocomkg.org | — | |
domaincenter.yntymak-ordo.com | — | |
domaincert.presldent.info | — | |
domaincheck.presldent.info | — | |
domainchief.presldent.info | — | |
domaindata.yntymak-ord.com | — | |
domaindata.yntymak-ordo.com | — | |
domaingov.mpekz.online | — | |
domainhelp.galkynysh.net | — | |
domaininfo.tdtu.org | — | |
domaininfoxxe.plan-mail.com | — | |
domainit.presldent.info | — | |
domainkg.tdtu.org | — | |
domainlink.ytnymak-ord.com | — | |
domainmail.infocomkg.org | — | |
domainmail.plan-mail.com | — | |
domainmail.postmfa.com | — | |
domainmicrosoft.natcommunzu.com | — | |
domainnormativ.dushanbeidc.org | — | |
domainnormativ.sozandagon.org | — | |
domainns.panterstationary.online | — | |
domainns1.wordcheck.info | — | |
domainpro.taustas.com | — | |
domainsanly.oilgas-tm.com | — | |
domainservice.infocomkg.org | — | |
domainstate.presldent.info | — | |
domainstorage.natcommunzu.com | — | |
domainsupport.natcommunzu.com | — | |
domaintelecom.hpsupporter.com | — | |
domaintmk.natcommunzu.com | — | |
domainud.tdtu.org | — | |
domainuz.adm-devon.com | — | |
domainuz.natcommunzu.com | — | |
domainwww.tm-mfa.com | — | |
domainwww.tmgaz-server.com | — | |
domainwww.tojiktelecomtj.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip46.30.188.54 | — | |
ip45.67.230.185 | — | |
ip2.58.14.95 | — | |
ip193.29.59.248 | — | |
ip185.243.112.253 | — | |
ip185.122.185.36 | — | |
ip46.30.191.230 | — | |
ip193.29.59.159 | — | |
ip31.58.220.250 | — | |
ip171.22.16.187 | — | |
ip5.183.95.7 | — | |
ip193.29.58.192 | — | |
ip185.243.112.220 | — | |
ip185.243.114.124 | — | |
ip185.243.114.238 | — | |
ip185.243.115.156 | — | |
ip188.190.18.208 | — | |
ip188.243.115.156 | — | |
ip193.29.56.119 | — | |
ip193.29.57.159 | — | |
ip193.29.57.182 | — | |
ip193.29.58.217 | — | |
ip195.88.191.250 | — | |
ip195.88.191.70 | — | |
ip2.58.14.91 | — | |
ip2.58.15.101 | — | |
ip2.58.15.129 | — | |
ip2.58.15.172 | — | |
ip31.57.92.84 | — | |
ip31.58.209.28 | — | |
ip31.59.185.224 | — | |
ip45.86.162.141 | — | |
ip45.86.162.249 | — | |
ip45.86.163.87 | — | |
ip46.30.189.191 | — | |
ip46.30.190.170 | — | |
ip46.30.191.214 | — | |
ip46.30.191.232 | — | |
ip46.30.191.90 | — | |
ip5.183.95.49 | — | |
ip83.242.96.242 | — | |
ip88.190.1.208 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash9297d5fd21ef21b16f5880cd4faea2ad1fb9ee39 | — | |
hash27e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4 | — | |
hashe9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382 | — |
Threat ID: 6aabc50d55bf5e2cf53b2015
Added to database: 09/17/2026, 10:46:37 UTC
Last enriched: 09/17/2026, 11:03:38 UTC
Last updated: 09/17/2026, 22:01:24 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.