Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

SilkParasite Campaign Links SpiceRAT, NodeEdgeRAT & NomadRAT to Central Asian Government Targets

Hunt.io traced a four‑year SilkParasite operation that ties three RAT families to shared TLS certificates and cloned web pages, targeting governments and critical sectors in Central Asia. The finding underscores the need for continuous third‑party infrastructure monitoring to satisfy audit‑ready risk programs.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
securityaffairs.com

SilkParasite Campaign Ties SpiceRAT, NodeEdgeRAT & NomadRAT to Central Asian Government Targets

What Happened – Researchers at Hunt.io identified a four‑year APT operation (codenamed SilkParasite) that uses shared TLS certificates, identical hostnames and a cloned web page to link three Remote‑Access Trojan families—SpiceRAT, NodeEdgeRAT and NomadRAT—to command‑and‑control (C2) infrastructure targeting governments and critical‑sector entities in Central Asia.

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of third‑party infrastructure (domains, certificates, hosting patterns) provides the evidence needed to prove due‑diligence in a vendor‑risk program.
  • Detecting shared artifacts across C2 servers enables a defensible audit trail that maps to the control objective of “Supply‑chain and third‑party risk monitoring.”
  • Leveraging threat‑intel feeds to flag state‑backed certificate authorities helps satisfy governance requirements for provenance verification of external services.

Who Is Affected – Government agencies, critical‑infrastructure operators, and any organization that may interact with services hosted on the identified domains (e.g., telecom, transport, energy) in Central Asia and beyond.

Recommended Actions

  • Integrate TLS‑certificate and domain‑ownership monitoring into your continuous control‑assurance platform.
  • Enrich your third‑party risk register with the identified C2 indicators and validate any external providers that use similar certificates.
  • Conduct a focused review of any inbound/outbound traffic to the listed IP ranges and hostnames; block or quarantine as appropriate.

Source: Security Affairs

Technical Notes

  • Malware families: SpiceRAT, NodeEdgeRAT, NomadRAT (all RATs).
  • Shared TLS certificate issued by TLC DV TLS CA (funded by China’s CAICT) impersonates Uzbekistan’s railway authority.
  • C2 servers observed in multiple countries; fingerprint includes a cloned RTX Corporation homepage page.

Source: same as above

📰 Original Source
https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →