Skip to main content

Command Palette

Search for a command to run...

SilkParasite: Seven RATs, One Ecosystem, and Infrastructure Tracing Back to 2022

Updated
•9 min read•View as Markdown
SilkParasite: Seven RATs, One Ecosystem, and Infrastructure Tracing Back to 2022

Summary

SilkParasite is Bitdefender's label for an espionage cluster targeting government bodies and energy infrastructure across Central Asia, assessed as China-nexus at medium confidence. What stands out is not the scale — roughly 65 observed infections — but the toolset: seven RAT families, five of them previously undocumented, using five different C2 channels including Google Drive and HTTP headers.

A month later, Hunt.io and researcher Guy Yasur followed the infrastructure and pushed the operation's origins back to mid-2022, well before the SilkParasite label existed.

Priority actions:

  • Hunt for DLL sideloading: a legitimately signed application loading a library placed beside it in an unusual location. The technique runs through all seven RAT families.

  • Monitor Google Drive traffic with no corresponding user activity. DriveSilkRAT uses the service itself as C2.

Victimology and Motivation

Bitdefender observed targets in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan, extending into Georgia and the South Caucasus. Sectors include:

  • Government bodies driving economic decision-making — the people who shape a country's political and economic relationships.

  • Energy infrastructure, partly overlapping the FamousSparrow campaign against Azerbaijani oil and gas in 05/2026. Bitdefender frames this against Russia's declining regional influence and China's expanding economic presence. The spoofed domains Hunt.io uncovered reinforce it: Uzbek railways, Turkmenistan's foreign ministry, Türkmengaz, the Galkynysh gas field, Tajik telecoms, and Kyrgyz economic bodies.

Initial Access

Spear-phishing with malicious Microsoft Office documents, often inside password-protected RAR archives to defeat content scanning. Lures are tailored to each targeted ministry.

Two details stand out:

  • A security-aware macro. It checks for avp.exe (Kaspersky) before deploying, showing the operators know what runs in the region.

  • Two AI-generated lures, a fake energy platform and a GPU cloud advertisement. Bitdefender describes them as deliberately cheap-looking. Once the document runs, the first stage is sideloading through a signed application to launch the payload.

The Toolset: Seven RAT Families

Family Language Status Primary C2
DriveSilkRAT .NET, C++ New Google Drive
SpiceRAT C/C++ Known (Talos) HTTP
CookiETagRAT C++ New HTTP Cookie/ETag headers
BloodAlchemy C/C++ Known TCP, HTTP/S, DNS, SMB
NomadRAT C++ New HTTPS (MessagePack)
GoginRAT Go New HTTP
NodeEdgeRAT JavaScript/Node.js New HTTPS

Apart from NodeEdgeRAT, all use a plugin architecture, execute in memory, and rotate encryption keys between builds.

Two stand out:

  • DriveSilkRAT uses Google Drive as its control channel. No unusual domain to block, no IP for a blocklist.

  • BloodAlchemy belongs to the ShadowPad and Deed RAT lineage. Deed RAT was FamousSparrow's main backdoor — one of the threads tying SilkParasite to the wider China-nexus ecosystem.

Notable TTPs

DLL sideloading via legitimately signed applications is the primary delivery method. Bitdefender lists the pairs:

Host application Loaded DLL RAT family
ebook-edit.exe (Calibre) calibre-launcher.dll SpiceRAT
FineReader.exe (ABBYY) dsp_ippv2_x64.dll BloodAlchemy
emlproui.exe (Quick Heal) scansts.dll NomadRAT
MpDefenderCoreService.exe (Windows Defender) mpclient.dll DriveSilkRAT
Mp3tag.exe tak_deco_lib.dll CookiETagRAT

Persistence via scheduled tasks: SpiceRAT relaunches every 2 minutes, NodeEdgeRAT uses SysEdgeUpdateTaskMachineCore, BloodAlchemy uses fl_bridge. Both names are chosen to pass as system tasks.

Defense evasion:

  • Dynamic API resolution by hash

  • HalosGate syscall evasion (BloodAlchemy)

  • Hardware breakpoints and vectored exception handlers

  • Rotation across multiple signed host applications

  • Process creation through WMI instead of cmd.exe, breaking the parent-child chains many EDR rules rely on Capabilities: process listing, file management, command execution, clipboard logging, keylogging, user-session impersonation.

Infrastructure: What Hunt.io Found

Hunt.io started from the SpiceRAT signature Cisco Talos published in 2024. From late 2025 their C2 detection module began flagging matching servers, and a SpiceRAT cluster surfaced in mid-March 2026.

SpiceRAT server cluster, March 2026

The TLS certificate is the pivot. A certificate with subject azure.uzrailwaystax[.]com, impersonating Uzbekistan's railway authority, was issued by TLC, a CA wholly funded by CAICT — a state research institute under China's Ministry of Industry and Information Technology. The certificate appeared on 8 servers spanning both SpiceRAT and NodeEdgeRAT infrastructure.

Certificate SHA-256 query results

A cloned RTX Corporation page. Several servers serve a byte-for-byte copy of defense contractor RTX's homepage on port 80, while SpiceRAT C2 runs on 443. The page hash led to 13 hosts. Security Affairs called it a "low-noise, high-precision signature" for defenders.

Cloned RTX Corporation page

RDP on high ports. Many hosts expose RDP-over-TLS on 64350, 64330, 65535, 65111 and 61256. Querying that pattern across the relevant ASNs surfaced further NomadRAT-linked domains.

High-port query

Hosting. Servers sit behind resellers CrownCloud, EDIS GmbH and CloudBackbone, on ASNs 199959, 57169, 48314 and 9009, spread across Germany, Bulgaria, the Netherlands, Estonia, Romania, Latvia and Russia.

Timeline. Passive DNS dates the earliest subdomains to mid-2022. As Security Affairs puts it, SilkParasite is a more recent label for an operation with a much longer and wider footprint.

Four Pivots Worth Reusing

Hunt.io's methodology transfers to most infrastructure-hunting platforms, not just their own:

  1. Hash the full page body. Attackers clone a legitimate site as cover, and the copy is identical on every server. One hash led to 13 hosts.

  2. Pivot on certificate SHA-256. A certificate reused across servers connected two malware families that looked separate.

  3. JA4X combined with issuer. Pairing the fingerprint of how a server builds certificates with the CA identity, then filtering by common ASNs, narrows thousands of hosts to a workable list.

  4. Services on non-standard ports. RDP on a five-digit port is an operational habit, and habits repeat across infrastructure clusters. The common thread: three of the four rely on no victim-supplied IOC at all, only on the attacker's configuration habits. That is a more durable hunting angle than a domain list.

Signs of AI-Assisted Development

Bitdefender assesses at medium confidence that part of the toolset was built with AI assistance, based on three observations:

  • Default encryption keys left in place: 0123456789abcdef in GoginRAT and change_this_key in NodeEdgeRAT — classic sample-code placeholders.

  • Leftover Go test functions in GoginRAT release builds, indicating an unpolished build process.

  • NomadRAT (C++) and GoginRAT (Go) share close architecture, suggesting one high-level design reused and emitted in two languages. Add the two AI-generated lures, and the picture is a group scaling tool output quickly with loose quality control. For defenders that cuts both ways: more variants to expect, but mistakes like default keys make very clean signatures.

Analysis

Seven RATs likely mean a shared ecosystem, not one unit's arsenal. Bitdefender says so plainly and does not fold SilkParasite into an existing named group. SpiceRAT was previously tied by Talos to SneakyChef, while BloodAlchemy sits in FamousSparrow's ShadowPad/Deed RAT lineage — tooling circulates. Read reports like this treating the group name as a label for an activity cluster, not an organization.

The 2022 date changes the risk picture. If infrastructure ran from mid-2022 and was only flagged in late 2025, dwell time in victim environments may be far longer than 65 infections suggests. That number is what was observed, not a victim total.

A Chinese-issued certificate is a good indicator, not attribution evidence. TLC is a commercial CA; anyone can obtain a certificate. Its value is rarity in this kind of infrastructure, which makes it an excellent pivot. Do not let it stand alone as an attribution argument.

The C2 channels are the hardest part. Google Drive and Cookie/ETag headers leave no network indicator to block. Defense has to move to the endpoint: which process loads which DLL, and which process opens which connection.

Relevance to Vietnam

  • The same geopolitical target profile. Vietnam falls within the operating scope of several China-nexus groups, and economic policy bodies and energy firms are the same class of target SilkParasite pursues in Central Asia.

  • The ShadowPad/Deed RAT lineage is familiar in Southeast Asia. Organizations that have previously seen alerts tied to it should retro-hunt the sideloading pairs listed here.

  • Sideloading via common software is a practical weak point: Calibre, ABBYY FineReader and Mp3tag are all user-installed. Environments without application allowlisting will struggle to see it.

  • Google Drive C2 bypasses most proxy policy, since the service is almost always permitted in enterprises.

Recommendations

  • Hunt DLL sideloading: alert when a signed process loads a DLL from outside its standard install path, with special attention to the pairs above. This rule outlives the campaign.

  • Monitor scheduled tasks by name and behavior: look for SysEdgeUpdateTaskMachineCore, fl_bridge, and tasks relaunching a process on very short intervals (SpiceRAT uses 2 minutes).

  • Baseline cloud-service traffic: connections to Google Drive from a process that is not a browser or the official sync client warrant investigation.

  • Review WMI child processes: creating processes via WmiPrvSE.exe instead of cmd.exe is used to dodge parent-child rules, so that branch needs rules of its own.

  • Ingest the IOCs below into SIEM/EDR, and feed the certificate SHA-256 and page hash into infrastructure hunting if you run an Internet-scanning platform.

  • Retro-hunt at least 12 months for organizations in the affected sectors, given the infrastructure timeline now reaches 2022.

IOCs

The list below is compiled from the public portions of the Hunt.io and Bitdefender publications. The full IOC set (sample hashes, CSV) lives in Bitdefender Labs' GitHub repository and the Hunt.io post.

Spoofed domains and infrastructure

azure.uzrailwaystax[.]com      # impersonates Uzbek railways
tm-mfa[.]com                   # impersonates Turkmenistan MFA
tmgaz-server[.]com             # impersonates Türkmengaz
help.galkynysh[.]net           # impersonates Galkynysh gas field
tojiktelecomtj[.]com           # impersonates Tajik telecom
mineconom.tdtu[.]org           # NomadRAT-linked
kg.tdtu[.]org
hoster-kg[.]com                # NodeEdgeRAT-linked
ns2.asiainfo.it[.]com          # hosts the cloned RTX page
uzrailway.devon-uz[.]com       # Bitdefender, BloodAlchemy-linked

IP addresses

46.30.191.230     188.190.29.126    193.29.59.159
31.58.220.250     171.22.16.187     2.58.14.95
45.153.125.200    194.68.44.133

TLS certificate

Issuer:     TLC DV TLS CA
Subject:    azure.uzrailwaystax[.]com
Serial:     81628176171941507003526847276457465393
SHA-256:    27E072B92B5AC9E3E2A6770BEF3E84BDF864B0611D3BC9CACA12BE2B1A63DAE4
Validity:   2025-12-23 → 2026-12-23
JA4X:       a373a9f83c6b_7022c563de38_4eebb5e6ba4e

Page hash (cloned RTX site)

SHA-256: E9D0E8B8A33858A7A5A46F78D7A78F9AA7F9B029348D9B618C6A6A1937A39382

Host-based

Scheduled tasks:  SysEdgeUpdateTaskMachineCore   (NodeEdgeRAT)
                  fl_bridge                      (BloodAlchemy)
 
Sideloading pairs: ebook-edit.exe            <- calibre-launcher.dll
                   FineReader.exe            <- dsp_ippv2_x64.dll
                   emlproui.exe              <- scansts.dll
                   MpDefenderCoreService.exe <- mpclient.dll
                   Mp3tag.exe                <- tak_deco_lib.dll

Notable service ports: 64350, 64330, 65535, 65111, 61256 (RDP-over-TLS)

Associated ASNs: 199959, 57169, 48314, 9009

References

More from this blog

F

FPT IS Security

1021 posts

Dedicated to providing insightful articles on cybersecurity threat intelligence, aimed at empowering individuals and organizations to navigate the digital landscape safely.