Hunt.io identified a 13-server suspected command-and-control cluster associated with SpiceRAT targeting government, telecommunications, and energy organizations across Uzbekistan, Turkmenistan, Tajikistan, Kyrgyzstan, and Kazakhstan. The servers impersonated regional government agencies, telecom providers, and energy entities, using cloned RTX Corporation web content alongside shared domains, TLS certificates, registration relationships, and recurring hosting patterns.
Researchers expanded the SilkParasite-linked infrastructure by pivoting from a shared page hash and TLS certificate, finding overlaps with infrastructure previously reported for NodeEdgeRAT and NomadRAT. Passive-DNS records indicate related subdomains may extend to mid-2022, but the findings are infrastructure-based rather than evidence of confirmed intrusions or malware-sample linkage; they support either a common operator or shared support infrastructure, without definitive attribution.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Five SpiceRAT-detected servers were simultaneously active in mid-March 2026: 46.30.191.230, 188.190.29.126, 193.29.59.159, 31.58.220.250, and 171.22.16.187.
The previously reported SpiceRAT indicator manager.skycom.support resolved to 194.68.225.168 and 194.14.217.119 in late January 2026.
The hostname ns2.asiainfo.it.com resolved to SpiceRAT-detected servers in Estonia, Bulgaria, and other provider networks during January and February 2026.
A TLS certificate for azure.uzrailwaystax.com, spoofing Uzbekistan's state railway authority, became valid. The certificate was later observed on eight hosts in the identified infrastructure.
Researchers tracked suspected SpiceRAT command-and-control infrastructure from late 2025 through August 2026.
Passive-DNS history showed related natcommunzu.com infrastructure dating to July 2022, indicating elements of the broader cluster may have operated since then.
Before publication, researchers notified apparent impersonation targets and relevant national CERTs regarding domains spoofing Central Asian government, telecommunications, and energy entities. They emphasized that the notifications did not establish compromise or confirm the named organizations as victims.
Shared domains, certificates, webpage hashes, registration relationships, and hosting patterns linked the SpiceRAT-associated infrastructure with infrastructure reported for NodeEdgeRAT and NomadRAT. Researchers assessed the evidence as consistent with either a common operator using multiple toolsets or shared support infrastructure, without definitive attribution.
Researchers pivoted on an identical cloned RTX Corporation webpage hash and a spoofed TLS certificate to identify 13 linked hosts, including servers previously reported as SpiceRAT command-and-control infrastructure. The RTX content was assessed as static decoy material, with no identified payloads, credential forms, or malicious code.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 113 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.