← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 17, 2026 · 12:26via Cyber Security News

SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia

Brief

SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity behind the campaign may be older and broader than its recent name suggests.

The operation has used spear-phishing emails carrying convincing government-themed documents and trusted Windows programs to plant remote-access malware. These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.

Hunt.io analysts, working with researcher Guy Yasur, identified a connected group of SpiceRAT command-and-control servers active from late 2025 to August 2026.

Hunt.io said in a report shared with Cyber Security News (CSN) that the infrastructure links to SilkParasite, which used seven remote-access toolsets against Central Asian governments.

Read more on Cyber Security News→