SpiceRAT C2 Infrastructure Linked to SilkParasite Attacks on Central Asian Government and Energy Sectors
Brief
Researchers have uncovered a wider command-and-control (C2) infrastructure cluster linked to SpiceRAT activity targeting government, energy, and telecommunications organizations across Central Asia.
The investigation, conducted jointly with researcher Guy Yasur, tracked servers active from late 2025 through August 2026.
The infrastructure overlaps with indicators published in Bitdefender’s August 2026 SilkParasite report, which documented suspected China-nexus activity in the region.
Ahead of publication on September 9, researchers notified affected organizations and relevant national CERTs with a TLP:AMBER advance copy.
The domains and certificates are attacker-controlled impersonations. Organizations named in the findings are apparent targets of spoofing and are not confirmed to have been compromised.
