SilkParasite Campaign Infrastructure Active for Four Years, Targeting Central Asia
Analysis of malware infrastructure linked to the SilkParasite cyberespionage campaign reveals activity dating back at least four years, targeting governments and critical sectors across Central Asia.

A cyberespionage operation known as SilkParasite, which has been targeting government, energy, and telecommunications entities in Central Asia, appears to be significantly older and more extensive than previously understood. New research indicates that the underlying malware infrastructure has been active for at least four years, suggesting that "SilkParasite" may be a more recent label for a long-running spying effort.
The campaign has employed spear-phishing emails containing convincing government-themed documents and seemingly legitimate Windows programs to deploy remote-access malware. These tools are designed to provide attackers with a persistent foothold within victim networks, enabling them to exfiltrate sensitive information and issue further commands.
Analysts from Hunt.io, in collaboration with researcher Guy Yasur, identified a cluster of SpiceRAT command-and-control (C2) servers that were active from late 2025 through August 2026. The infrastructure associated with these servers shows strong technical links to the SilkParasite campaign, which has been observed utilizing at least seven different remote-access toolsets against its targets.
The significance of this discovery lies in its ability to connect seemingly disparate systems through repeated technical indicators, rather than relying on a single malware sample. By analyzing publicly accessible infrastructure, researchers can map the evolution and reuse of systems employed by long-term espionage operations. The shared parent domains, identical digital certificates, and cloned web pages found across the identified C2 servers link SpiceRAT infrastructure to systems previously attributed to NodeEdgeRAT and NomadRAT, suggesting a common operational or support function.
One particularly notable artifact used to map this infrastructure was a complete, albeit outdated, copy of an RTX Corporation homepage. This decoy page, while containing no malicious code, was found on multiple servers. Its identical content hash provided a reliable method for researchers to track and correlate infrastructure that might otherwise appear unrelated. The reuse of a digital certificate impersonating an Uzbek railway entity across eight hosts further strengthened these connections.
Further extending the timeline, passive DNS records revealed related subdomains dating back to mid-2022. This evidence suggests that the infrastructure supporting these operations has been in place for at least four years, predating the public emergence of the SilkParasite moniker. The targeting appears to focus on entities within Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan, with infrastructure names mimicking government agencies and state-owned enterprises.
While the infrastructure names suggest targeting, they do not confirm breaches of the named organizations. Hunt.io has notified affected entities and relevant national CERTs. The observed targeting overlaps with the China-linked SilkParasite campaign, which has been previously assessed with medium confidence as having a China-nexus. However, the network evidence alone does not independently establish attribution, though it does show naming similarities with other suspected China-nexus activities like IndigoZebra and FamousSparrow.
For defenders, the key takeaway is the importance of correlating various indicators, including network logs, DNS records, and certificate data, especially within the targeted sectors. Organizations should scrutinize unusual remote desktop exposures, investigate lookalike domains, and strengthen phishing defenses. Verifying unexpected government-themed documents and monitoring for repeated web page or certificate artifacts can help expose staging and command systems that might evade endpoint detection, providing a more comprehensive view of potential exposures.