$ techbeacon▋
Phishing

SilkParasite Campaign Ties Multiple RATs to Central Asian Government Espionage

SilkParasite Campaign Ties Multiple RATs to Central Asian Government Espionage

A multi‑year cyber‑espionage operation dubbed SilkParasite has been linked to a suite of remote‑access tools—including SpiceRAT, NodeEdgeRAT and NomadRAT—by cybersecurity firm Hunt.io, according to a report that highlights a sustained focus on governments and critical infrastructure across Central Asia.

The investigation, led by Hunt.io researcher Guy Yasur, uncovered a tightly clustered set of command‑and‑control (C2) servers used by SpiceRAT. These servers were found to be active before the earliest known deployments of the other malware families, suggesting that the SilkParasite infrastructure has been evolving for at least four years. The shared hosting patterns, encryption keys and deployment scripts point to a common operator or group managing the entire ecosystem.

SilkParasite’s targets span a range of sectors deemed essential to national stability, including energy grids, telecommunications, and governmental ministries. While the precise identities of the compromised entities have not been disclosed, the geographic concentration in Kazakhstan, Kyrgyzstan, Tajikistan and Uzbekistan aligns with a broader trend of state‑aligned actors seeking intelligence on regional political dynamics and economic projects, such as cross‑border pipelines and trade corridors.

Experts note that the use of multiple RATs allows the campaign to diversify its capabilities. SpiceRAT, for instance, is known for its modular architecture and ability to exfiltrate data stealthily, whereas NodeEdgeRAT and NomadRAT provide distinct persistence mechanisms and lateral‑movement tools. By rotating between these tools, the operators can evade detection by security products that rely on signature‑based detection, and they can tailor payloads to the specific security posture of each victim.

The findings underscore the challenges faced by Central Asian states in hardening their cyber defenses. Regional security agencies have been urged to share threat intelligence and to adopt a layered security approach that includes network segmentation, continuous monitoring and regular patching of vulnerable systems. Hunt.io’s report also calls for increased collaboration with international partners to trace the financial and logistical support behind SilkParasite, which may extend beyond the region. As the campaign continues to adapt, analysts warn that further disclosures are likely, and that the infrastructure could be repurposed for new targets if left unchecked.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related