SpiceRAT is a Windows remote-access trojan used in targeted cyberespionage activity. Cisco Talos previously associated it with the suspected China-based SneakyChef group, and it was later observed as one of several remote-access tools used in the SilkParasite campaign, a medium-confidence China-nexus activity cluster targeting government organizations in Central Asia. SilkParasite activity also targeted government, energy, and telecommunications interests in the region. Infection chains used spear-phishing messages carrying malicious Microsoft Office documents, including password-protected archives, and executed payloads through DLL sideloading with legitimate signed Windows applications. SpiceRAT has been documented establishing scheduled-task persistence and supports downloading and executing binaries and arbitrary commands. Its command-and-control infrastructure has been linked through shared domains, certificates, and hosting artifacts with infrastructure associated with other SilkParasite RATs, although this infrastructure overlap does not establish common operator control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hunt.io identified a cluster of five active SpiceRAT command-and-control servers in mid-March 2026 and linked them through common hostnames, TLS certificates, and a cloned RTX Corporation webpage.
The initial foothold involved two families, SpiceRAT and DriveSilkRAT... SpiceRAT is the family that was previously documented by Cisco Talos, June 2024, in reporting on SneakyChef.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“The infrastructure used names resembling government agencies, state energy operators and telecom organizations across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.”
"SysEdgeUpdateTaskMachineCore NodeEdgeRAT persistence scheduled task"; "fl_bridge BloodAlchemy persistence scheduled task"; and multiple "SpiceRAT persistence scheduled task" entries.
DriveSilkRAT ... run it through an in-memory .NET plugin system ... NodeEdgeRAT ... spanning command execution ... SpiceRAT ... equipped to download and run executable binaries and arbitrary commands.
Its newer variants resolve the Windows APIs they need dynamically by hash rather than through ordinary imports.
The cluster's domains don't just look governmental; they spoof specific ministries and state enterprises... [including] Turkmenistan's Ministry of Foreign Affairs... Tojiktelecom... Turkmen energy... Uzbek administration... and even the Kyrgyz president's residence.
“SpiceRAT command-and-control servers” and “These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.”
“The cloned page is served on port 80, while SpiceRAT's command channel operates separately on port 443.”
It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan used in the long-running SilkParasite cyberespionage operation. Its C2 infrastructure used spoofed Central Asian government and state-enterprise domains, shared TLS certificates, and a recurring cloned RTX webpage fingerprint.
A remote-access malware family used in the SilkParasite cyberespionage operation. Its infrastructure was associated with spear-phishing lures and trusted Windows programs used to establish footholds, collect information, and issue commands in victim networks.
A remote-access tool used in the SilkParasite cyberespionage operation to establish a foothold in victim networks, collect information, and receive operator commands. Its C2 infrastructure was linked through shared domains, certificate reuse, and cloned RTX web-page artifacts.
Remote-access trojan whose command-and-control infrastructure was active against Central Asian government and energy-related entities, using infrastructure impersonating regional state and telecommunications organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.