NodeEdgeRAT is a JavaScript-based remote access trojan used in the SilkParasite cyberespionage operation. It executes through a bundled legitimate Node.js runtime and packages command execution, file management, and file-transfer functionality in a single obfuscated script. The implant has used scheduled-task persistence and single-instance control. SilkParasite used NodeEdgeRAT alongside several other RAT families in targeted intrusions against government organizations in Central Asia and Georgia. The operation primarily used spear-phishing lures carrying malicious Office documents, often within password-protected archives, and DLL sideloading through legitimate signed Windows applications. SilkParasite was assessed as China-nexus with medium confidence, without attribution to a specific threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bitdefender attributed evo.hoster-kg[.]com to NodeEdgeRAT; its shared registration under hoster-kg[.]com links it to infrastructure presenting the same railway-spoofing certificate used in the SpiceRAT cluster.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
"SysEdgeUpdateTaskMachineCore NodeEdgeRAT persistence scheduled task"; "fl_bridge BloodAlchemy persistence scheduled task"; and multiple "SpiceRAT persistence scheduled task" entries.
DriveSilkRAT ... run it through an in-memory .NET plugin system ... NodeEdgeRAT ... spanning command execution ... SpiceRAT ... equipped to download and run executable binaries and arbitrary commands.
NodeEdgeRAT ... is an obfuscated JavaScript implant run through a bundled legitimate Node.js runtime.
“SpiceRAT command-and-control servers” and “These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.”
“The cloned page is served on port 80, while SpiceRAT's command channel operates separately on port 443.”
100 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan family documented as one of SilkParasite's RAT families. Its infrastructure shares parent-domain registration and certificate patterns with infrastructure tied to SpiceRAT.
A remote-access malware family whose attributed infrastructure shares domains, certificate artifacts, and cloned-page infrastructure with SpiceRAT-linked systems. The evidence suggests a potential common operation or shared support function, but does not prove unified control.
A remote-access tool whose infrastructure and registration activity were linked to the SpiceRAT infrastructure cluster through shared technical artifacts.
A SilkParasite-associated remote-access trojan linked to the SpiceRAT infrastructure cluster through shared domains and TLS certificates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.