SilkParasite, a cyberespionage campaign targeting government, energy, and telecommunications sectors in Central Asia, has been traced back over four years through recent infrastructure analysis. This operation has been deploying spear-phishing emails with government-themed documents and trusted Windows programs to implant remote-access malware, enabling attackers to infiltrate networks, collect information, and issue commands. Researchers from Hunt.io, in collaboration with Guy Yasur, uncovered a network of SpiceRAT command-and-control servers active from late 2025 to August 2026, which has been linked to SilkParasite through shared domains, digital certificates, and identical web pages.
The significance of this discovery lies in its ability to connect disparate systems by recognizing repeated technical patterns, rather than relying on single malware samples. This expansive infrastructure, resembling official government and state organization names, spans Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan, and Kazakhstan. While these names suggest possible impersonation targets, they do not confirm breaches of the organizations themselves. Hunt.io has already informed the affected entities and relevant national CERTs.
The infrastructure's connection to a China-linked espionage campaign known as SilkParasite was assessed with medium confidence. Although the evidence provides context, it does not conclusively attribute the operation to a single actor. The infrastructure also shares similarities with previous activities linked to IndigoZebra and FamousSparrow, pointing to potential shared tools or conventions rather than a direct operational link.
For cybersecurity teams, the key takeaway is the necessity of monitoring network logs, DNS records, and certificate data for known indicators. Investigating suspicious remote desktop exposure and lookalike domains is crucial. Strengthening phishing defenses, verifying unexpected documents through separate channels, and restricting unnecessary remote access are recommended actions. Such measures can help identify hidden staging and command systems that may otherwise evade endpoint detection, thus providing a comprehensive view of possible threats.

