Researchers Map SpiceRAT-Linked Infrastructure Impersonating Central Asian Government and Energy Targets

· Original article ↗

Summary

Hunt.io researchers linked SpiceRAT infrastructure to hosts associated with NodeEdgeRAT and NomadRAT, identifying domains impersonating government, energy, and telecom organizations across Central Asia. The findings indicate infrastructure links, not confirmed victimir

Key points

  • Researchers tracked a cluster of SpiceRAT command-and-control servers active from late 2025 through August 2026, linking hosts through shared hostnames, TLS certificates, and webpage hashes.
  • Shared registration-level infrastructure connects hosts attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT; the research cannot establish whether one operator or multiple operators used the infrastructure.
  • Domains and certificates impersonated organizations including Uzbekistan's railway authority, Turkmenistan's energy and foreign-affairs entities, and Tajikistan's telecom provider.
  • Thirteen servers hosted an identical copy of RTX Corporation's homepage; researchers found no credential forms, payloads, or delivery mechanisms in the page.
  • Passive DNS records show related subdomain infrastructure dating to at least mid-2022.
  • The analysis used internet-wide scan data and did not investigate malware behavior, delivery, or initial access; named organizations are apparent impersonation targets, not confirmed compromised victims.

Article Details

Attack Vectors
  • The article examines command-and-control infrastructure and explicitly does not assess malware delivery or initial access.
  • SpiceRAT command traffic operated on port 443, separate from a cloned RTX Corporation homepage served on port 80 as likely static decoy content.
  • Domains and certificates impersonated Central Asian government bodies, state enterprises, and energy and telecommunications entities. The named organizations are apparent impersonation targets, not confirmed compromised parties.
  • Some cluster hosts exposed RDP-over-TLS on unusually high ports.
  • Shared hostnames, TLS certificates, webpage content, and domain registrations connected infrastructure associated with SpiceRAT, NodeEdgeRAT, and NomadRAT; the research does not establish whether one operator or multiple operators controlled it.
Defensive Notes
  • Organizations in the affected regions and sectors can check the published infrastructure indicators against their own exposure.
  • A byte-identical copy of the RTX Corporation homepage produced a SHA-256 page hash observed on 13 cluster servers; the article says no other host in Hunt.io's dataset served that page.
  • The article cautions that a SpiceRAT server detection identifies what is running on a host, not who operates it.
  • The TLC certificate issuer alone is not an indicator: the researchers observed nearly 3,000 servers with TLC certificates in a 30-day scan window.
  • The researchers notified affected organizations and relevant national CERTs before publication; notification does not mean recipients confirmed the findings.

Indicators of compromise

TypeIndicatorContext
DOMAINhoster-kg[.]comShared registered parent domain linking a cluster hostname to a Bitdefender-attributed NodeEdgeRAT hostname.
DOMAINinfocomkg[.]orgParent domain of enumerated cluster-linked hostnames.
DOMAINkginfocom[.]comHistorical infrastructure attributed in the article to IndigoZebra.
DOMAINnatcommunzu[.]comParent domain of enumerated cluster infrastructure, including a hostname detected as SpiceRAT.
DOMAINpost[.]mfa-uz[.]comHistorical infrastructure attributed in the article to IndigoZebra.
DOMAINtdtu[.]orgShared registered parent domain linking a cluster hostname to a Bitdefender-published NomadRAT C2 hostname.
DOMAINtm-mfa[.]comDomain described as impersonating Turkmenistan's Ministry of Foreign Affairs.
DOMAINtmgaz-server[.]comDomain described as spoofing Türkmengaz on a cluster server.
DOMAINtojiktelecomtj[.]comDomain described as targeting Tojiktelecom on a cluster server.
HOSTNAMEapi[.]hpsupporter[.]comHostname on a cluster-linked host exposing high-port RDP-over-TLS.
HOSTNAMEazure[.]adm-devon[.]comCluster hostname impersonating Uzbekistan government administration.
HOSTNAMEazure[.]uzrailwaystax[.]comCluster hostname and TLS certificate subject impersonating Uzbekistan's railway authority.
HOSTNAMEcenter[.]infocomkg[.]orgHostname on a cluster-linked server exposing high-port RDP-over-TLS.
HOSTNAMEcenter[.]yntymak-ordo[.]comHostname in the indicator table for impersonation of the Kyrgyzstan president's residence.
HOSTNAMEcert[.]presldent[.]infoHostname in enumerated government-themed cluster infrastructure.
HOSTNAMEcheck[.]presldent[.]infoHostname in enumerated government-themed cluster infrastructure.
HOSTNAMEcheckup[.]hpsupporter[.]comHostname in enumerated cluster-linked infrastructure.
HOSTNAMEchief[.]presldent[.]infoHistorical hostname in enumerated government-themed cluster infrastructure.
HOSTNAMEdata[.]yntymak-ord[.]comKyrgyzstan government-themed hostname in the indicator table.
HOSTNAMEdata[.]yntymak-ordo[.]comCluster hostname identified as impersonating the Kyrgyzstan president's residence.
HOSTNAMEevo[.]hoster-kg[.]comSibling hostname Bitdefender attributed to NodeEdgeRAT.
HOSTNAMEgov[.]mpekz[.]onlineCluster hostname referencing a Kazakh government entity.
HOSTNAMEhelp[.]galkynysh[.]netHostname impersonating Turkmenistan's Galkynysh gas field.
HOSTNAMEhelp[.]hoster-kg[.]comCluster hostname sharing a registered parent domain with a Bitdefender-attributed NodeEdgeRAT hostname.
HOSTNAMEhelp[.]hpsupporter[.]comHostname in enumerated cluster-linked infrastructure.
HOSTNAMEinfo[.]tdtu[.]orgHistorical hostname in enumerated cluster-linked infrastructure.
HOSTNAMEinfoxxe[.]plan-mail[.]comHostname of a cluster server serving the cloned RTX page.
HOSTNAMEinfrastructure[.]minings[.]blogHostname of a Bitdefender-reported SpiceRAT server.
HOSTNAMEit[.]presldent[.]infoHostname in enumerated government-themed cluster infrastructure.
HOSTNAMEkg[.]cwisuz[.]comHostname listed on a server impersonating Central Asian entities.
HOSTNAMEkg[.]tdtu[.]orgCluster hostname sharing a registered parent domain with a Bitdefender-published NomadRAT C2 hostname.
HOSTNAMElink[.]ytnymak-ord[.]comKyrgyzstan government-themed hostname in the indicator table.
HOSTNAMEmail[.]infocomkg[.]orgHostname in enumerated cluster-linked infrastructure.
HOSTNAMEmail[.]plan-mail[.]comHostname of a cluster server serving the cloned RTX page.
HOSTNAMEmail[.]postmfa[.]comHostname on a cluster-linked server exposing high-port RDP-over-TLS.
HOSTNAMEmanager[.]skycom[.]supportBitdefender-listed SpiceRAT hostname that also resolved to two additional servers.
HOSTNAMEmicrosoft[.]natcommunzu[.]comHostname in enumerated communications-themed cluster infrastructure.
HOSTNAMEmineconom[.]tdtu[.]orgBitdefender-published NomadRAT C2 hostname.
HOSTNAMEnormativ[.]dushanbeidc[.]orgCluster hostname impersonating Tajikistan's national IT-hub project.
HOSTNAMEnormativ[.]sozandagon[.]orgHostname listed on a server impersonating Central Asian entities.
HOSTNAMEns[.]panterstationary[.]onlineHostname of a cluster server serving the cloned RTX page.
HOSTNAMEns1[.]wordcheck[.]infoHostname listed for a Hunt.io-detected SpiceRAT cluster server.
HOSTNAMEns2[.]asiainfo[.]it[.]comHostname reused across multiple SpiceRAT servers.
HOSTNAMEpro[.]taustas[.]comHostname of a cluster server serving the cloned RTX page.
HOSTNAMEsanly[.]oilgas-tm[.]comCluster hostname impersonating Turkmen energy interests.
HOSTNAMEservice[.]infocomkg[.]orgHostname in enumerated cluster-linked infrastructure.
HOSTNAMEstate[.]presldent[.]infoCluster hostname using a government-themed typosquat.
HOSTNAMEstorage[.]natcommunzu[.]comCluster-linked hostname whose host Hunt.io flagged for SpiceRAT.
HOSTNAMEsupport[.]natcommunzu[.]comHistorical hostname in enumerated communications-themed cluster infrastructure.
HOSTNAMEtelecom[.]hpsupporter[.]comHostname in enumerated cluster-linked infrastructure.
HOSTNAMEtmk[.]natcommunzu[.]comCluster hostname described as a possible spoof of Uzbekistan's communications sector.
HOSTNAMEud[.]tdtu[.]orgHistorical hostname in enumerated cluster-linked infrastructure.
HOSTNAMEuz[.]adm-devon[.]comUzbekistan government-themed hostname in the indicator table.
HOSTNAMEuz[.]natcommunzu[.]comHistorical hostname in enumerated communications-themed cluster infrastructure.
HOSTNAMEuzrailway[.]devon-uz[.]comBitdefender-published BloodAlchemy C2 hostname impersonating Uzbekistan's railway entity.
HOSTNAMEwww[.]tm-mfa[.]comCluster hostname impersonating Turkmenistan's Ministry of Foreign Affairs.
HOSTNAMEwww[.]tmgaz-server[.]comCluster hostname associated with impersonation of Türkmengaz.
HOSTNAMEwww[.]tojiktelecomtj[.]comCluster hostname impersonating Tojiktelecom.
HOSTNAMEwww[.]wordcheck[.]infoHostname listed for a SpiceRAT cluster server presenting the spoofed railway certificate.
IPV4171[.]22[.]16[.]187SpiceRAT cluster server also observed presenting the spoofed railway certificate.
IPV4185[.]122[.]185[.]36SpiceRAT server previously resolved by a cluster hostname.
IPV4185[.]243[.]112[.]220Historical host in the enumerated communications-themed cluster infrastructure.
IPV4185[.]243[.]112[.]253Host of a cluster-linked subdomain flagged by Hunt.io's SpiceRAT detection.
IPV4185[.]243[.]114[.]124Cluster host serving the cloned RTX page and an impersonating domain.
IPV4185[.]243[.]114[.]238Cluster host sharing a self-signed certificate with another cluster server and resolving to an impersonating domain.
IPV4185[.]253[.]116[.]145Historical host in the enumerated tdtu[.]org infrastructure.
IPV4185[.]253[.]117[.]32Host in the enumerated government-themed cluster infrastructure.
IPV4188[.]190[.]18[.]208Cluster host serving the cloned RTX page and presenting shared TLS certificates.
IPV4188[.]190[.]29[.]126Hunt.io-detected SpiceRAT server that also served the cloned RTX page.
IPV4188[.]243[.]115[.]156Cluster host serving the cloned RTX page.
IPV4192[.]121[.]87[.]172Host listed with a Kyrgyzstan government-themed domain.
IPV4193[.]29[.]56[.]119Host presenting the spoofed Uzbekistan railway TLS certificate.
IPV4193[.]29[.]57[.]159Cluster host presenting a certificate for a possibly impersonating communications domain.
IPV4193[.]29[.]57[.]182Host presenting the spoofed Uzbekistan railway TLS certificate.
IPV4193[.]29[.]58[.]192Host resolving to a domain whose sibling hostname Bitdefender attributed to NodeEdgeRAT.
IPV4193[.]29[.]58[.]217Host listed with a Kyrgyzstan government-themed domain.
IPV4193[.]29[.]59[.]159Hunt.io-detected SpiceRAT cluster server.
IPV4193[.]29[.]59[.]248Historical host in the enumerated tdtu[.]org infrastructure.
IPV4194[.]14[.]217[.]119Server previously resolved by a Bitdefender-listed SpiceRAT hostname.
IPV4194[.]14[.]217[.]199Host in the enumerated infocomkg[.]org infrastructure.
IPV4194[.]68[.]225[.]168Server previously resolved by a Bitdefender-listed SpiceRAT hostname.
IPV4194[.]68[.]44[.]133Bitdefender-reported SpiceRAT server serving the cloned RTX page.
IPV4194[.]71[.]107[.]243SpiceRAT server previously resolved by a cluster hostname.
IPV4195[.]88[.]191[.]250Host listed with a Turkmen energy-themed domain.
IPV4195[.]88[.]191[.]70Host listed with a domain impersonating the Kyrgyzstan president's residence.
IPV42[.]58[.]14[.]95Hunt.io-detected SpiceRAT server serving the cloned RTX page and presenting the spoofed railway certificate.
IPV42[.]58[.]15[.]101Historical host in the enumerated government-themed cluster infrastructure.
IPV42[.]58[.]15[.]129Host in the enumerated hpsupporter[.]com infrastructure.
IPV42[.]58[.]15[.]172Cluster host serving the cloned RTX page.
IPV431[.]57[.]92[.]84Cluster host serving the cloned RTX page.
IPV431[.]58[.]209[.]28Cluster host serving the cloned RTX page.
IPV431[.]58[.]220[.]250Hunt.io-detected SpiceRAT cluster server.
IPV431[.]59[.]185[.]224Cluster host serving the cloned RTX page.
IPV445[.]153[.]125[.]20Bitdefender-reported SpiceRAT server serving the cloned RTX page and presenting the spoofed railway certificate.
IPV445[.]153[.]125[.]200Bitdefender-reported SpiceRAT server serving the cloned RTX page.
IPV445[.]153[.]127[.]186Cluster host resolving to a Kazakh government-themed domain.
IPV445[.]153[.]127[.]38Host listed with an Uzbekistan government-themed domain.
IPV445[.]153[.]127[.]99Cluster-linked host exposing high-port RDP-over-TLS and resolving to government-themed domains.
IPV445[.]67[.]230[.]185Historical host in the enumerated communications-themed cluster infrastructure.
IPV445[.]86[.]162[.]141Cluster-linked host exposing high-port RDP-over-TLS.
IPV445[.]86[.]162[.]249Host in the enumerated hpsupporter[.]com infrastructure.
IPV445[.]86[.]163[.]87Host in the enumerated government-themed cluster infrastructure.
IPV446[.]30[.]188[.]54Cluster host serving the cloned RTX page under an impersonating telecommunications domain.
IPV446[.]30[.]189[.]191Cluster host with a TLC-issued certificate for a government-themed typosquat.
IPV446[.]30[.]190[.]170Host in the enumerated communications-themed cluster infrastructure.
IPV446[.]30[.]191[.]214Host in the enumerated government-themed cluster infrastructure.
IPV446[.]30[.]191[.]230Hunt.io-detected SpiceRAT cluster server.
IPV446[.]30[.]191[.]232Host listed among servers impersonating Central Asian entities.
IPV446[.]30[.]191[.]90Host in the enumerated hpsupporter[.]com infrastructure.
IPV45[.]183[.]95[.]49Host listed with an Uzbekistan government-themed domain.
IPV45[.]183[.]95[.]76Cluster-linked host exposing high-port RDP-over-TLS.
IPV483[.]242[.]96[.]242Host in the enumerated infocomkg[.]org infrastructure.
IPV491[.]132[.]94[.]36Host of a domain impersonating Turkmenistan's Galkynysh gas field.
IPV492[.]243[.]66[.]71Host presenting the spoofed Uzbekistan railway TLS certificate.
SHA19297d5fd21ef21b16f5880cd4faea2ad1fb9ee39SHA-1 fingerprint listed for the spoofed Uzbekistan railway TLS certificate.
SHA25627e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4Fingerprint of the spoofed Uzbekistan railway TLS certificate deployed across cluster hosts.
SHA256e9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382Hash of the cloned RTX homepage used to identify 13 servers in the infrastructure cluster.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Tools

Countries

Bulgariain three different countries: 185.122.185[.]36 in Estonia on 24 January 2026, 194.71.107[.]243 in Bulgaria on 30 January, and 188.190.29[.]126 on 26 February, and where it currently resolves as of this post'sChina¬å¸ (TL Certification Center, TLC). TLC is wholly funded by the China Academy of Information and Communications Technology (CAICT), a research institute under China's Ministry of Industry and Information Technology.Estoniaresolved to three SpiceRAT servers in three different countries: 185.122.185[.]36 in Estonia on 24 January 2026, 194.71.107[.]243 in Bulgaria on 30 January, and 188.190.29[.]126 on 26 February, andGermanyAn identical certificate (matched by SHA-256) appeared on 185.243.114[.]238 (AS48314, IP-Projects, Germany) between 28 and 31 July. A HuntSQL query on the organization value confirmed the certificate appeared onKazakhstanKyrgyzstanUzbekistan government administration (azure.adm-devon[.]com), and the residence of the Kyrgyzstan president (data.yntymak-ordo[.]com) were identified on the same infrastructure profile. Full domain andTajikistanresolved to a single domain, normativ.dushanbeidc[.]org, a NameCheap-registered domain impersonating Tajikistan's national IT-hub project. The domain registrar, hosting provider and country targeting align with theTurkmenistanIdentified domains spoof named entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs.Uzbekistanby a Chinese state-affiliated certificate authority associated with the infrastructure impersonates Uzbekistan's state railway authority. Additionally, this cluster also shares registration-level relationships with

Industries

Related Articles