Researchers have discovered a larger command-and-control (C2) network linked to SpiceRAT activity targeting government, energy, and telecommunications organizations across Central Asia. The investigation, conducted in collaboration with researcher Guy Yasur, tracked servers active from late 2025 through August 2026. This infrastructure overlaps with indicators previously revealed in Bitdefender’s August 2026 SilkParasite report, which highlighted suspected Chinese nexus activity in the region.
Ahead of publication on September 9, researchers notified affected organizations and relevant national CERTs with a TLP:AMBER advance copy. The SpiceRAT C2 Links SilkParasite Detection logic, based on Cisco Talos' 2024 research, first identified related servers in late 2025.
Screenshot of the RTX Corporation impersonation page hosted on ns2.asiainfo.it[. ]com (Source: hunt.io) The certificate was issued in December 2025 by TLC DV TLS CA, operated by a Chinese certificate authority connected to the China Academy of Information and Communications Technology. However, its use on domains spoofing Central Asian state entities, alongside other shared infrastructure artifacts, strengthens the operational link.
Spoofed entities include Türkmengaz, the Galkynysh gas field, Tojiktelecom, Turkmenistan's Ministry of Foreign Affairs, and Uzbekistan-related government services. Indicators of Compromise Type Indicator Associated artifact / Notes IP Address 46.30.191[. ]230 SpiceRAT server detected in March 2026; ports 80 and 443 IP Address 188.190.29[. ]126 SpiceRAT; resolved ns2.asiainfo.it[.
]com; hosted a cloned RTX page and a railway-themed TLS certificate











