SilkParasite Campaign Ties SpiceRAT, NodeEdgeRAT & NomadRAT to Central Asian Government Targets
What Happened – Researchers at Hunt.io identified a four‑year APT operation (codenamed SilkParasite) that uses shared TLS certificates, identical hostnames and a cloned web page to link three Remote‑Access Trojan families—SpiceRAT, NodeEdgeRAT and NomadRAT—to command‑and‑control (C2) infrastructure targeting governments and critical‑sector entities in Central Asia.
Why It Matters for Trust & Control Assurance
- Continuous monitoring of third‑party infrastructure (domains, certificates, hosting patterns) provides the evidence needed to prove due‑diligence in a vendor‑risk program.
- Detecting shared artifacts across C2 servers enables a defensible audit trail that maps to the control objective of “Supply‑chain and third‑party risk monitoring.”
- Leveraging threat‑intel feeds to flag state‑backed certificate authorities helps satisfy governance requirements for provenance verification of external services.
Who Is Affected – Government agencies, critical‑infrastructure operators, and any organization that may interact with services hosted on the identified domains (e.g., telecom, transport, energy) in Central Asia and beyond.
Recommended Actions
- Integrate TLS‑certificate and domain‑ownership monitoring into your continuous control‑assurance platform.
- Enrich your third‑party risk register with the identified C2 indicators and validate any external providers that use similar certificates.
- Conduct a focused review of any inbound/outbound traffic to the listed IP ranges and hostnames; block or quarantine as appropriate.
Source: Security Affairs
Technical Notes
- Malware families: SpiceRAT, NodeEdgeRAT, NomadRAT (all RATs).
- Shared TLS certificate issued by TLC DV TLS CA (funded by China’s CAICT) impersonates Uzbekistan’s railway authority.
- C2 servers observed in multiple countries; fingerprint includes a cloned RTX Corporation homepage page.
Source: same as above