NomadRAT is a modular C++ remote-access trojan used in the SilkParasite cyberespionage operation. It comprises a main orchestrator, a dedicated library for command-and-control communications, and plugins retrieved from the operator-controlled server by numeric identifier only when required, minimizing the initial implant footprint. SilkParasite used malicious Office-document lures, often distributed in password-protected archives through spear-phishing, and DLL sideloading of legitimate signed Windows applications to deploy its toolset; NomadRAT loader artifacts were associated with this sideloading tradecraft. The operation targeted government organizations across Central Asia, with targeting also reported in Georgia. SilkParasite was assessed as China-nexus with medium confidence, but has not been conclusively attributed to a specific threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
kg.tdtu[.]org shares a parent domain with mineconom.tdtu[.]org, a NomadRAT C2 indicator in the SilkParasite report.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The cluster's domains don't just look governmental; they spoof specific ministries and state enterprises... [including] Turkmenistan's Ministry of Foreign Affairs... Tojiktelecom... Turkmen energy... Uzbek administration... and even the Kyrgyz president's residence.
“SpiceRAT command-and-control servers” and “These tools can give operators a foothold in a victim network, allowing operators to collect information and issue commands.”
“The cloned page is served on port 80, while SpiceRAT's command channel operates separately on port 443.”
It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small.
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan family documented in the SilkParasite operation. Its C2 infrastructure has parent-domain links to the wider cluster that includes SpiceRAT and NodeEdgeRAT.
A remote-access malware family associated in this report with infrastructure sharing technical artifacts with SpiceRAT-linked servers. The overlap is investigative lead material rather than proof of a direct operational relationship.
A remote-access tool with infrastructure connected to the investigated SpiceRAT cluster through shared parent domains and related infrastructure artifacts.
A SilkParasite-associated remote-access trojan linked to the SpiceRAT infrastructure cluster through shared domains and TLS certificates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.