Skip to main content

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

0
Medium
Published: 09/16/2026 (09/16/2026, 17:20:48 UTC)
Source: AlienVault OTX General

Description

Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 11:03:38 UTC

Technical Analysis

This threat involves a sophisticated cluster of command and control servers linked to the SpiceRAT malware family and related RATs such as NodeEdgeRAT, NomadRAT, and BloodAlchemy. The infrastructure is characterized by shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage, indicating coordinated management or shared resources. A notable aspect is the use of a TLS certificate impersonating Uzbekistan's railway authority issued by a Chinese state-affiliated certificate authority, facilitating spoofing of Central Asian government and energy sector domains. Passive DNS analysis reveals the infrastructure has been active since mid-2022, with recent activity continuing through August 2026. The infrastructure overlaps with tactics and infrastructure used by known China-associated threat actors FamousSparrow and IndigoZebra, suggesting a possible state-affiliated campaign targeting Central Asian government and energy sectors. This is an ongoing espionage infrastructure rather than a software vulnerability or exploit.

Potential Impact

The infrastructure supports multiple remote access trojans (RATs) used to target government and energy sector entities in Central Asia, potentially enabling espionage, data exfiltration, and network compromise. The use of spoofed domains and TLS certificates increases the likelihood of successful deception and evasion of detection. The prolonged operational period (at least four years) indicates sustained targeting and potential compromise of sensitive organizations. There are no known exploits or vulnerabilities in software products directly associated with this infrastructure.

Defensive Guidance

This is an active threat infrastructure rather than a software vulnerability; therefore, no patches or software fixes apply. Defenders should monitor for indicators of compromise related to the identified RAT families and spoofed domains. Network defenders should validate TLS certificates and domain authenticity, especially those impersonating government and critical infrastructure entities. Organizations in Central Asia should be particularly vigilant for spear-phishing and other intrusion attempts linked to these threat actors. No vendor advisories or official fixes are applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure"]
Adversary
SilkParasite
Pulse Id
6aaacff0ea056cea51165b6b

Indicators of Compromise

Domain

ValueDescriptionCopy
domainpost.mfa-uz.com
domainkginfocom.com
domainnatcommunzu.com
domainwww.wordcheck.info
domainapi.hpsupporter.com
domainhelp.hpsupporter.com
domaincheckup.hpsupporter.com
domainuzrailway.devon-uz.com
domaintm-mfa.com
domainevo.hoster-kg.com
domainhoster-kg.com
domainhelp.hoster-kg.com
domaininfrastructure.minings.blog
domainkg.cwisuz.com
domainmanager.skycom.support
domainmineconom.tdtu.org
domaininfocomkg.org
domaintmgaz-server.com
domaintojiktelecomtj.com
domainazure.adm-devon.com
domainazure.uzrailwaystax.com
domaincenter.infocomkg.org
domaincenter.yntymak-ordo.com
domaincert.presldent.info
domaincheck.presldent.info
domainchief.presldent.info
domaindata.yntymak-ord.com
domaindata.yntymak-ordo.com
domaingov.mpekz.online
domainhelp.galkynysh.net
domaininfo.tdtu.org
domaininfoxxe.plan-mail.com
domainit.presldent.info
domainkg.tdtu.org
domainlink.ytnymak-ord.com
domainmail.infocomkg.org
domainmail.plan-mail.com
domainmail.postmfa.com
domainmicrosoft.natcommunzu.com
domainnormativ.dushanbeidc.org
domainnormativ.sozandagon.org
domainns.panterstationary.online
domainns1.wordcheck.info
domainpro.taustas.com
domainsanly.oilgas-tm.com
domainservice.infocomkg.org
domainstate.presldent.info
domainstorage.natcommunzu.com
domainsupport.natcommunzu.com
domaintelecom.hpsupporter.com
domaintmk.natcommunzu.com
domainud.tdtu.org
domainuz.adm-devon.com
domainuz.natcommunzu.com
domainwww.tm-mfa.com
domainwww.tmgaz-server.com
domainwww.tojiktelecomtj.com

Ip

ValueDescriptionCopy
ip46.30.188.54
ip45.67.230.185
ip2.58.14.95
ip193.29.59.248
ip185.243.112.253
ip185.122.185.36
ip46.30.191.230
ip193.29.59.159
ip31.58.220.250
ip171.22.16.187
ip5.183.95.7
ip193.29.58.192
ip185.243.112.220
ip185.243.114.124
ip185.243.114.238
ip185.243.115.156
ip188.190.18.208
ip188.243.115.156
ip193.29.56.119
ip193.29.57.159
ip193.29.57.182
ip193.29.58.217
ip195.88.191.250
ip195.88.191.70
ip2.58.14.91
ip2.58.15.101
ip2.58.15.129
ip2.58.15.172
ip31.57.92.84
ip31.58.209.28
ip31.59.185.224
ip45.86.162.141
ip45.86.162.249
ip45.86.163.87
ip46.30.189.191
ip46.30.190.170
ip46.30.191.214
ip46.30.191.232
ip46.30.191.90
ip5.183.95.49
ip83.242.96.242
ip88.190.1.208

Hash

ValueDescriptionCopy
hash9297d5fd21ef21b16f5880cd4faea2ad1fb9ee39
hash27e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4
hashe9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382

Threat ID: 6aabc50d55bf5e2cf53b2015

Added to database: 09/17/2026, 10:46:37 UTC

Last enriched: 09/17/2026, 11:03:38 UTC

Last updated: 09/17/2026, 22:01:24 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses