SilkParasite is a cyberespionage campaign primarily targeting government agencies, energy providers, and telecommunications organizations throughout Central Asia. Recent infrastructure analysis suggests the operation may be significantly older and more expansive than previously believed.
The threat actors behind the campaign have relied on spear-phishing emails containing convincing government-themed documents and legitimate Windows applications to deploy remote access malware. Once installed, these tools provide attackers with persistent access to compromised environments, enabling data collection, surveillance, and remote command execution.
Researchers from Hunt.io, in collaboration with security researcher Guy Yasur, uncovered a cluster of SpiceRAT command-and-control (C2) servers that remained active from late 2025 through August 2026. According to a report shared with Cyber Security News, the identified infrastructure appears linked to SilkParasite and supports the operation's use of seven distinct remote access toolsets against government entities across Central Asia.
The significance of this discovery lies in its ability to connect infrastructure components through recurring technical indicators rather than a single malware sample. Analysis of internet-facing assets often provides valuable insight into how long-running espionage campaigns establish, maintain, and reuse their operational infrastructure.
Infrastructure Links Reveal Broader Operations
Researchers connected SpiceRAT servers to infrastructure associated with NodeEdgeRAT and NomadRAT through shared parent domains, a common digital certificate, and duplicated web content. While these findings do not conclusively prove a single operator controls every system, they strongly suggest either a common threat actor or a shared support framework behind the activity.
SpiceRAT-related infrastructure was initially identified in late 2025 using earlier detection methodologies. In March 2026, investigators observed five additional servers emerging within a short period across multiple hosting providers and geographic locations. Shared hostnames and certificate artifacts provided stronger evidence of connectivity than malware detections alone, which only reveal activity on individual systems.
One of the most notable infrastructure markers was a full but outdated clone of an RTX Corporation website. Although the page contained no malicious functionality, credential harvesting mechanism, or malware delivery component, its identical content hash was found across 13 separate servers.
This repeated web-page artifact provided researchers with a reliable method for linking otherwise unrelated systems, mirroring infrastructure patterns commonly observed in sophisticated remote access malware campaigns.
Certificate reuse provided another critical connection. Investigators identified a digital certificate impersonating an Uzbek railway organization that appeared on eight separate hosts, including systems hosting the cloned RTX page.
The certificate was issued by TLC, a certificate authority operated by an organization backed by a Chinese state-affiliated communications research institute. Researchers emphasized, however, that the presence of this certificate issuer alone should not be viewed as evidence of malicious intent.
Passive DNS data expanded the timeline even further. Related subdomains were observed as early as mid-2022, indicating the supporting infrastructure has likely been in operation for at least four years. These findings raise the possibility that SilkParasite may simply represent a newer designation for a much longer-running cyberespionage effort.
Focus on Central Asian Government and Critical Infrastructure Targets
The identified infrastructure utilized domain names designed to resemble government agencies, national energy companies, and telecommunications providers in Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan.
Researchers cautioned that these domains should be interpreted as likely impersonation targets rather than proof that any of the named organizations were successfully compromised. Prior to publication, Hunt.io notified potentially affected entities and relevant national Computer Emergency Response Teams (CERTs).
The targeting patterns closely align with previously documented SilkParasite activity, which has been linked to espionage campaigns employing government-themed document lures alongside a combination of established and newly identified remote access tools.
Earlier assessments suggested a possible connection to China-linked threat activity with moderate confidence. While the newly uncovered infrastructure evidence provides additional context, it does not independently confirm attribution.
Researchers also identified naming conventions and infrastructure characteristics resembling activity associated with IndigoZebra, another suspected China-linked threat cluster, as well as overlaps previously reported with FamousSparrow.
Such similarities may stem from shared tooling, infrastructure providers, or operational conventions. Consequently, they should be considered investigative indicators rather than definitive proof of a direct operational relationship.
Key Defensive Recommendations
For defenders, the findings highlight the importance of examining network telemetry, DNS records, and certificate data for the indicators identified by researchers, particularly within government, energy, and telecommunications sectors.
Security teams should closely monitor remote desktop services, investigate lookalike domains, and rapidly assess suspicious infrastructure activity. Recent incidents involving malware operators abusing developer tunneling services further demonstrate the need for continuous monitoring of outbound connections and remote-management pathways.
Organizations can reduce risk by:
- Strengthening phishing awareness and email security controls.
- Independently verifying unexpected government-themed documents.
- Limiting unnecessary remote access capabilities.
- Monitoring for recurring certificate and web-page artifacts.
- Conducting proactive threat hunting across DNS, network, and infrastructure logs.
By correlating these indicators across multiple data sources, defenders can uncover staging environments and command-and-control infrastructure that traditional endpoint security solutions may overlook. This broader visibility is particularly important for organizations responsible for critical services and systems with privileged or sensitive access.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
